Reference Guide
...
Audit Report
Linux Audit Report
the linux local user audit report is used to report the current security status of local linux accounts create the report configuration navigate to audit report > linux audit report open the report configuration tab create a report configuration by completing the fields the report job can be executed manually or periodically (as scheduled) to execute the report manually, click the options pop up menu button and select run to execute the report periodically, the scheduled field needs to be configured in the report configuration the period can also be configured from the jobs scheduler by editing the linuxauditjob for the purposes of the audit report, the selected device groups must have the globalusername and globalpassword properties defined see also section https //app archbee com/docs/jsymind0w sxaymlkgomr/2lprcyqir220xuzut0zt to access the report detail, the user defined as “ globalusername ” should be a privileged user also, if the globalusername is a sudo user and the sudo command execution is required to get report details, the usesudoforlinuxauditreport device group property must be defined as true on the device group after this definition, the sudoers column is added to the linux audit report details table and the globalusername sudo user will write yes here report details when the job finishes, reports are listed in the reports tab to access the reports navigate to audit report > linux audit report open the report tab click the options drop down menu button and select show details report details are shown in the linux audit report details section dashboard navigate to audit report > linux audit report open the dashboard tab choose the desired fields and click the display reports button if you want to exclude service accounts from the audit reports, you need to define accounttoexcludefromlinuxauditreport as a property at the device group level by defining this property and setting service accounts, users can distinguish service accounts and application accounts by excluding defined accounts from linux audit reports