Administrator LogThe menu allows the administrator to view the actions performed on the SHIELD DRM admin page.Audit LogThis is the screen. It records management activities such as policy, integration, and configuration changes for security audit purposes.
Document conversion logs handle the results of document processing, while the administrator logs areAdministrator ActionsThis is an audit log that deals with.
Screen Configuration
SHIELD DRM Admin Page로그 > 관리자 로그Click on the menu to access.
The administrator log uses the same view screen as the integrated log system. The logged-in administrator account and language settings are automatically transmitted, so no separate login procedure is required.
Query Items
| item | Explanation |
|---|
| event | This is the event name that indicates administrator actions. |
| Administrator Account | The user ID of the administrator who performed the action. |
| IP address | This is the IP address of the client that sent the request. |
| Processing date and time | This is the time when the action occurred. |
| Detailed Information | Details of actions such as changed configuration values. |
Search and Filter
| Filter items | Explanation |
|---|
| Period | Specify the start date and end date for the query. |
| Administrator Account | Only retrieves actions of a specific administrator. |
| Event Name | Select the event name of the "Recorded Administrator Actions" below to view only that action. |
Recorded Administrator Actions
| division | Occurrence Menu | Recorded Actions |
|---|
| Conditional Policy | Conditional Policy | Policy Registration, Modification, Deletion, Order Change |
| Event Receiver | Integration Management > Microsoft 365 | Event Receiver Installation, Removal, Migration Requests and Site-Specific Processing Results |
| Add-in | Integration Management > Microsoft 365 | Add-in Installation and Removal Requests and Site-Specific Processing Results |
| External Company Connection | Integration Management > External Company Connection | Connection request · approval · rejection, request withdrawal, disconnect |
| Settings | Configuration Management | Save document conversion delay time setting |
| Google Drive Webhook | Integration Management > Google Workspace | Webhook Installation and Uninstallation Requests and Processing Results by Drive |
Failed actions are also recorded. Actions such as viewing and browsing lists are not recorded.
Conditional Policy
| Event Name | recording time |
|---|
| Conditional Policy Registration | When registering or copying a policy |
| Conditional Policy Modification | When saving the policy through the editor window or JSON editing |
| Delete Conditional Policy | When a policy is deleted |
| Change Order of Conditional Policies | When the priority of the policy was changed |
- Microsoft 365, Google Workspace, SHIELD DRM Agent, DS for Mobile policies are recorded. The type of policy is distinguished by the policy type in the logs. The Google Drive conditional policy is
Google DriveIt is recorded as a policy type.
- The usage status and validity period changes of the policy are recorded as "Conditional Policy Modification" since it saves the entire policy. You can check the policy before and after the changes in the detailed information.
- If the save fails, it will be recorded as a failure under the same event name.
Event Receiver (Microsoft 365)
The requested item is recorded first, followed by the processing results recorded one by one for each target site.
| Event Name | recording time |
|---|
| Event Receiver Installation Request / Event Receiver Installation Request Failed | When requesting selective installation, full installation, or CSV bulk installation |
| Event Receiver Removal Request / Event Receiver Removal Request Failed | When requesting to deselect or select all |
| Migration Request / Migration Request Failed | When requesting to switch from the add-in method to the event receiver method |
| Site-specific event receiver installation / Site-specific event receiver installation failure | When handling the installation of a site in one place |
| Remove site-specific event receivers / Failed to remove site-specific event receivers | When handling the removal of a site |
| Site-specific migration completed / Site-specific migration failed | When handling the migration of a site |
- OneDrive and SharePoint are recorded with the same event name.
- Request logs mean that the request has been received. The actual installation results can be checked in the site-specific logs.
- If a new site or new user is detected and installed automatically, only site-specific logs will be recorded.
Add-in (Microsoft 365)
| Event Name | recording time |
|---|
| Add-in installation request / Add-in installation request failed | When requesting add-in installation or CSV bulk registration |
| Add-in removal request / Add-in removal request failed | When requesting to remove the add-in |
| Add-in Installation by Site / Add-in Installation Failure by Site | When requesting installation at one site |
| Remove Add-ins by Site / Failed to Remove Add-ins by Site | When requesting removal from one site |
| Site-specific add-in upgrade / Site-specific add-in upgrade failure | When upgrading a site with a previous version installed |
- For the target, OneDrive shows the owner, and SharePoint displays the site title.
- Sites that have already been installed or removed will be recorded as failure events.
External Company Connection
| Event Name | recording time | recorded company |
|---|
| External Company Connection Request | When requesting a connection to an external company | Requested Company |
| Approval for External Company Connection | When the received request is approved | Approved Company |
| Rejection of External Company Connection | When the received request is rejected | Rejected Company |
| Withdrawal of External Company Connection Request | When the sent request is recalled | Retrieved Company |
| Disconnect External Company | When disconnecting from a connected external company | Released Company |
| Disconnecting External Company | When an external company disconnects from this company | Released Company |
- Target includesExternal Company NameThis will be displayed. The details include the names of external companies,
Extra ID, connection status before and after the action, reason for rejection (if entered) will be recorded.
- It is only recorded as successful if the connection status has actually changed. Attempts where the status has not changed, such as re-requesting a company that has already been requested, are not recorded.
- unverifiable
Extra IDIn the case of a request and a failure to save, it is recorded as a failure under the same event name. At this time, the target contains the inputtedExtra IDis displayed.
- Disconnection is the company that has been disconnected and the company that has disconnected.on each sideIt will be recorded. Approval, rejection, request, and retrieval will only be recorded for the company that performed the action.
- "Disconnection of External Company" does not record external company administrator accounts.
- The external company name is the value at the time of recording. Even if the company name changes later, past logs will not change, so
Extra IDcompares to.
Settings
| Event Name | recording time |
|---|
| Update Embedded Profile Information / Failed to Update Embedded Profile Information | When saving document conversion delay time settings |
Google Drive Webhook (Google Workspace)
| action | recording time |
|---|
| Webhook Installation | When I requested the installation of webhooks for my drive and shared drive, it was processed for each drive. |
| Unsubscribe Webhook | When I requested to revoke the webhook for my drive and shared drive, when it was processed for each drive |
- Request reception and processing results by drive are recorded separately, and the results are categorized as success, retry, and failure.
- The renewal that automatically reinstalls before the webhook expires is not an administrator action, so it will not be recorded in the administrator log.
Caution
- The administrator log isAudit DataTherefore, general administrators cannot modify or delete it.
- Administrator log access requires administrator privileges. Menu usage requires
관리자 로그You need role permissions.
- The log retention period follows the index management policy of the integrated log system.
- Disconnecting from an external company will not delete past logs related to that company.