Send audit events to system logs
You can send NetBackup audit events to system logs. You must have the NetBackup Security Administrator role or similar RBAC permissions to perform this task.
By default, NetBackup sends the audit events to system logs in native format. You can now export audit events with the Open Cybersecurity Schema Framework (OCSF) format to Security Information and Event Management (SIEM) platforms.
See this article for more information.
Use the SYSLOG_AUDIT_USE_OCSF_FORMAT configuration option to send the NetBackup audit events to system logs in the OCSF format.
To send audit events to system logs
- Open the NetBackup web UI.
- On the left, select Security > Security events.
- On the top right, click Security event settings.
- Enable the Send the audit events to the system logs option.
- Select Select audit event categories. Then select the audit categories for which you want to send the audit events to the system logs.
To send audit events for all audit categories to the system logs, select the Audit event categories check box.
- Select Save.
You can view NetBackup audit events in the system logs. For example:
On a Windows system, use Windows Event Viewer to view NetBackup audit events.
On a Linux system, you can view the system logs on the configured location.