Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Audit Logs

Audit logs are a record of all administrative activities in an organization that can trigger changes in the network. These actions include changes to the network model, device configurations, and system settings. On the Audit Logs dashboard, you can view information for different types of activities and events such as creation or deletion of WLANs, updating an AP, or adding policies.

Features

    • You can trace configuration changes on your network by leveraging long-term storage of audit logs.
    • With audit logs, you can monitor user activity, investigate security breaches, and ensure compliance with regulatory requirements.
    • On the Audit Logs dashboard, you can filter data as needed and view granular-level details of each event.

Before You Begin

  • Refer to Mist Premium Analytics License to know about license requirements for Juniper Mist™ Premium Analytics.

  • Become familiar with the options available on the Juniper Mist Premium Analytics dashboards. See Figure 3.

Access Audit Log Analytics

  1. From the left menu on the Juniper Mist portal, select Analytics > Premium Analytics..
  2. On the Premium Analytics page, click Audit Logs.
    The Audit Logs dashboard appears.
  3. Use the filter options at the top of the dashboard to view specific information.
    • Click Report Date and set the period for which you want to generate analytics. By default, the dashboard shows data for the last 7 days.

    • Use the Admin E-mail and Admin Name filters to find the records for specific administrators. From the drop-down list, select the user that you want to include.

    • In the Message Template fields, enter a task title to find records for a particular task, such as adding a WLAN or updating the device profile. As you type, the dashboard reloads to show only the messages that contain the specified characters.

    • From the Message Template Exclude drop-down list, select the events that you want to exclude from the results.

    • From the dashboard actions on the top-right corner of the dashboard, select Reset filter to reset the filters.

Audit Log Dashboard

The Audit Log dashboard includes various tiles that provide graphical representations of analytics at a granular level.

On the top of the dashboard, you can view a detailed audit report for the selected time period.

Figure 1: Audit Report Audit Report

You can view the chart displaying the following details:

  • Event Date and Time—Time stamp of the event’s occurrence.
  • Admin Name—Username of the administrator whose audit logs you want to view.
  • Admin Email—E-mail address of the user whose audit logs you want to view.
  • Message—Description of a task.
  • Source IP—IP address of the user's device.
  • User Agent—Software stack used to make a web request.
  • After—Logs after the occurrence of a specific event.
  • Before—Logs before the occurrence of a specific event.

For certain types of events such as change in WLAN, you can find additional details.

To view additional details, click the message and select either the By Before or By After option.

Figure 2: View Additional Details for Audit Log View Additional Details for Audit Log

The audit record opens in a new window. On this report, you can see information as shown in Figure 3.

Figure 3: Audit Log Before and After Event Details Audit Log Before and After Event Details

You can see that the After and Before columns provide additional information.

Top Actions by User and Type

The tile displays users, the percent of events that each user performs, and the percentage of occurrences of each event type.

Figure 4: Top Actions by User and Device Type Top Actions by User and Device Type

In the Top Actions by Users chart, you can view the users who triggered the events that occurred in the selected time period. The legend shows the names of users with the percentage of events that each user triggered. You can place the cursor on a wedge in the pie chart to see the number of logs for an event and the associated username.

In the Top Actions by Type chart, you can view the distribution of event types, based on the number of occurrences of each event type, expressed as percentages. The legend shows the event types and the corresponding percentage of each type. You can place the cursor on a wedge in the pie chart to see the number of occurrences for an event type.

To hide data for a user or an event type in the charts and see data for only the remaining ones, click the username or the event type in the legends.