14.9. Typical Scenarios

Basic Security Auditing

To set up basic security event auditing:

  1. Enable auditing as described in Enabling Audit.

  2. In the Enable Audit Events group, switch to By Category view and check the Security category to enable all security events.

  3. Enable local storage as described in Using Local Storage. Set retention to the number of days required by your security policy.

  4. Click Apply.

Compliance-Ready Configuration

For a compliance-ready audit configuration with tamper protection:

  1. Enable auditing and enable all event categories by checking each top-level category in the By Category view.

  2. Enable local storage with retention set to 0 (infinite) or the number of days required by your compliance framework.

  3. Configure local Git tracking as described in Using Git Tracking to maintain a detailed commit history of configuration changes.

  4. Lock the configuration by checking Lock configuration.

  5. Enable permanent lock by clicking Enable Permanent Lock to prevent the configuration from being unlocked. See the warning in Enabling Permanent Lock before proceeding.

  6. Click Apply.

Configuration Change Tracking

To track configuration changes with version history:

  1. Enable auditing as described in Enabling Audit.

  2. In the By Category view, check the Configuration category.

  3. Configure Git tracking as described in Using Git Tracking to track change commits locally.

  4. Click Apply.