Add an Audit Log Export Receiver
Add an audit log export receiver to define the external SFTP destination, authentication method, export schedule, and Management Cloud Engine (MCE) that exports the audit logs.
- Expand the Administration slider and click Audit Log Export.
- Select Add.
- Complete the fields described in the following table.
IP Address/FQDN IP address or FQDN of the remote receiver. Enter an IPv4 address or FQDN. Note:
IPv6 is not currently supported.Protocol SFTP. This field is read-only. Port 22. This field is read-only. Remote Path Absolute destination directory on the receiver host. The path must begin with a forward slash (/). Username User name for the SFTP connection. Auth Type Select Password or Public Key. For information on generating a key pair, see Generate an SSH Key Pair.
Password Password for the SFTP connection. This field is only available when you select Password from the Auth Type drop-down list. Passphrase Optional passphrase for the private key. This field is only available when you select Public Key from the Auth Type drop-down list. Private Key Name Name of the private key file in /opt/oracle/mce/export/audit-export/keys. This field is only available when you select Public Key from the Auth Type drop-down list.Push Time (24 Hrs UTC) UTC time at which the scheduled export begins. The default is 22:00. To avoid the audit log purge window, set a time before 00:00 UTC or after 01:00 UTC. Push Interval (Days) The number of days between scheduled Audit Log Export operations. The minimum is 1 day, and the maximum is the Audit Log Purge interval configured for the tenant. To view the purge interval, go to Security Manager, Audit Log, Purge. Periodic exports include audit logs generated during the configured Push Interval. For example, if the Push Interval is 2 days and an export runs at 10:00 UTC on Wednesday, it includes audit logs generated from 10:00 UTC on Monday through 10:00 UTC on Wednesday.Note:
Audit records that are purged before an export runs cannot be retrieved through either scheduled export or on-demand synchronization.MCE MCE that performs the outbound export. The list includes only the MCEs that the logged-in administrator is authorized to access through the applicable MCE ACL. - Click Apply.