Audit configuration
Quick answer
Configuring audit logging in SailPoint IdentityIQ: audit events, what to capture and using audit data for compliance.
Key takeaways
- Audit records who did what and when
- Choose audited actions in Global Settings
- Audit data feeds searches and compliance reports
- Plan retention and archiving deliberately
Why audit
Audit logging records who did what and when, providing the evidence compliance and investigations depend on. It is configured, not on-by-default for everything.
Audit configuration
In Global Settings you choose which actions to audit, for example role changes, certification decisions, logins and provisioning, balancing coverage against volume.
Reading audit data
Audit events are searchable and feed audit reports and dashboards, letting you answer questions like who approved a given access.
Retention
Plan retention and archiving so audit data is available for your compliance window without overwhelming the database.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
Where do you choose which actions are audited?
- A. The connector
- B. Global Settings
- C. The role
- D. The workflow
Show answer
B. Global Settings
Audit actions are selected in Global Settings, balancing coverage and volume.