Is it possible to somehow audit and log administration changes like change of global variable or change of policy?
Changes like this are seen in the audit logs with the default settings at least as far as possible updates.
I don't know of any logging specific to the state of variables. Are you not seeing this? If not, have you modified any of the cluster properties for auditing/logging?
Did the answers on this thread answered your question? If it did please mark it as the right answer.When your question is not answered or you still have additional questions please let us know.
With Kind RegardsDirk
if the gateway audit log leveles are set to SEVERE to minimize the performance impact of logging, is there a way to make it log these 'administrative' audits anyway and apply the SEVERE levele just to policy execution audits?
The reason for this question is that we have the gws running in a bank a they want to have all configuration changes reported to their SIEM.