Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Log File Details

date_range 09-Aug-21

SUMMARY Administrators use JSA Risk Manager log files to view user activity and to troubleshoot system issues.

The following table describes the location and content of JSA Risk Manager log files.

Table 1: JSA Risk Manager Log Files
Log file name Location Description
audit.log /var/log/audit/ Contains the current audit information.
audit.<1-50>.gz /var/log/audit/ Contains archived audit information. When the audit.log file reaches 200 MB, it is compressed and renamed to audit.1.gz. The file number increments each time a log file is archived. JSA Risk Manager can store up to 50 archived log files.
qradar.log /var/log/ Contains all process information that is logged by the JSA Risk Manager server.
qradar.error /var/log/ All exceptions and System.out and System.err messages that are generated by the JSA Risk Manager server are logged in this file.
footer-navigation