Skip to main content

Administrator Log

Administrator LogThe menu allows the administrator to view the actions performed on the SHIELD DRM admin page.Audit LogThis is the screen. It records management activities such as policy, integration, and configuration changes for security audit purposes.

Document conversion logs handle the results of document processing, while the administrator logs areAdministrator ActionsThis is an audit log that deals with.


Screen Configuration​

SHIELD DRM Admin Page로그 > 관리자 로그Click on the menu to access.

The administrator log uses the same view screen as the integrated log system. The logged-in administrator account and language settings are automatically transmitted, so no separate login procedure is required.


Query Items​

itemExplanation
eventThis is the event name that indicates administrator actions.
Administrator AccountThe user ID of the administrator who performed the action.
IP addressThis is the IP address of the client that sent the request.
Processing date and timeThis is the time when the action occurred.
Detailed InformationDetails of actions such as changed configuration values.

Search and Filter​

Filter itemsExplanation
PeriodSpecify the start date and end date for the query.
Administrator AccountOnly retrieves actions of a specific administrator.
Event NameSelect the event name of the "Recorded Administrator Actions" below to view only that action.

Recorded Administrator Actions​

divisionOccurrence MenuRecorded Actions
Conditional PolicyConditional PolicyPolicy Registration, Modification, Deletion, Order Change
Event ReceiverIntegration Management > Microsoft 365Event Receiver Installation, Removal, Migration Requests and Site-Specific Processing Results
Add-inIntegration Management > Microsoft 365Add-in Installation and Removal Requests and Site-Specific Processing Results
External Company ConnectionIntegration Management > External Company ConnectionConnection request · approval · rejection, request withdrawal, disconnect
SettingsConfiguration ManagementSave document conversion delay time setting
Google Drive WebhookIntegration Management > Google WorkspaceWebhook Installation and Uninstallation Requests and Processing Results by Drive

Failed actions are also recorded. Actions such as viewing and browsing lists are not recorded.

Conditional Policy​

Event Namerecording time
Conditional Policy RegistrationWhen registering or copying a policy
Conditional Policy ModificationWhen saving the policy through the editor window or JSON editing
Delete Conditional PolicyWhen a policy is deleted
Change Order of Conditional PoliciesWhen the priority of the policy was changed
  • Microsoft 365, Google Workspace, SHIELD DRM Agent, DS for Mobile policies are recorded. The type of policy is distinguished by the policy type in the logs. The Google Drive conditional policy isGoogle DriveIt is recorded as a policy type.
  • The usage status and validity period changes of the policy are recorded as "Conditional Policy Modification" since it saves the entire policy. You can check the policy before and after the changes in the detailed information.
  • If the save fails, it will be recorded as a failure under the same event name.

Event Receiver (Microsoft 365)​

The requested item is recorded first, followed by the processing results recorded one by one for each target site.

Event Namerecording time
Event Receiver Installation Request / Event Receiver Installation Request FailedWhen requesting selective installation, full installation, or CSV bulk installation
Event Receiver Removal Request / Event Receiver Removal Request FailedWhen requesting to deselect or select all
Migration Request / Migration Request FailedWhen requesting to switch from the add-in method to the event receiver method
Site-specific event receiver installation / Site-specific event receiver installation failureWhen handling the installation of a site in one place
Remove site-specific event receivers / Failed to remove site-specific event receiversWhen handling the removal of a site
Site-specific migration completed / Site-specific migration failedWhen handling the migration of a site
  • OneDrive and SharePoint are recorded with the same event name.
  • Request logs mean that the request has been received. The actual installation results can be checked in the site-specific logs.
  • If a new site or new user is detected and installed automatically, only site-specific logs will be recorded.

Add-in (Microsoft 365)​

Event Namerecording time
Add-in installation request / Add-in installation request failedWhen requesting add-in installation or CSV bulk registration
Add-in removal request / Add-in removal request failedWhen requesting to remove the add-in
Add-in Installation by Site / Add-in Installation Failure by SiteWhen requesting installation at one site
Remove Add-ins by Site / Failed to Remove Add-ins by SiteWhen requesting removal from one site
Site-specific add-in upgrade / Site-specific add-in upgrade failureWhen upgrading a site with a previous version installed
  • For the target, OneDrive shows the owner, and SharePoint displays the site title.
  • Sites that have already been installed or removed will be recorded as failure events.

External Company Connection​

Event Namerecording timerecorded company
External Company Connection RequestWhen requesting a connection to an external companyRequested Company
Approval for External Company ConnectionWhen the received request is approvedApproved Company
Rejection of External Company ConnectionWhen the received request is rejectedRejected Company
Withdrawal of External Company Connection RequestWhen the sent request is recalledRetrieved Company
Disconnect External CompanyWhen disconnecting from a connected external companyReleased Company
Disconnecting External CompanyWhen an external company disconnects from this companyReleased Company
  • Target includesExternal Company NameThis will be displayed. The details include the names of external companies,Extra ID, connection status before and after the action, reason for rejection (if entered) will be recorded.
  • It is only recorded as successful if the connection status has actually changed. Attempts where the status has not changed, such as re-requesting a company that has already been requested, are not recorded.
  • unverifiableExtra IDIn the case of a request and a failure to save, it is recorded as a failure under the same event name. At this time, the target contains the inputtedExtra IDis displayed.
  • Disconnection is the company that has been disconnected and the company that has disconnected.on each sideIt will be recorded. Approval, rejection, request, and retrieval will only be recorded for the company that performed the action.
  • "Disconnection of External Company" does not record external company administrator accounts.
  • The external company name is the value at the time of recording. Even if the company name changes later, past logs will not change, soExtra IDcompares to.

Settings​

Event Namerecording time
Update Embedded Profile Information / Failed to Update Embedded Profile InformationWhen saving document conversion delay time settings

Google Drive Webhook (Google Workspace)​

actionrecording time
Webhook InstallationWhen I requested the installation of webhooks for my drive and shared drive, it was processed for each drive.
Unsubscribe WebhookWhen I requested to revoke the webhook for my drive and shared drive, when it was processed for each drive
  • Request reception and processing results by drive are recorded separately, and the results are categorized as success, retry, and failure.
  • The renewal that automatically reinstalls before the webhook expires is not an administrator action, so it will not be recorded in the administrator log.

Caution​

  • The administrator log isAudit DataTherefore, general administrators cannot modify or delete it.
  • Administrator log access requires administrator privileges. Menu usage requires관리자 로그You need role permissions.
  • The log retention period follows the index management policy of the integrated log system.
  • Disconnecting from an external company will not delete past logs related to that company.