Forum Discussion

ashks2014's avatar
ashks2014
Level 5
9 years ago
Solved

Audit journal searches

Is it possible to audit search queries if we give users access to the journal stores? So we can see who searched for what via Outlook or the Web search interface?

We don't have auditing configured but we have an EV mail archiving server and a dedicated journaling EV server. Do we need to enable it for both or just the server that handles the EV Journaling tasks?

  • GertjanA's avatar
    GertjanA
    9 years ago

    Hello,

    There is no documentation available. If you need backing on this statement, you might need to ask your legal/compliance department for assistance, as they should be aware of rules and regulations for your region. In addition, perhaps also the HR department. I do not believe either of these want users to access the journaled data, and be able to search for ANY item from ANYONE. For instance, would you like John Doe to search for all email from and to your CEO? Or perhaps from your manager? Including possible classified information send by email?

    the whole idea of having a Journal archive (i.e. Journaled email) is to be able to deliver evidence in a case (be it officially legal, be it internal research) without having evidence tampered with. If you have not secured the Journal Archive well enough, there migth be a risk that information is tampered with. If a user (as mentioned above) holds a grudge (if that is the word), and decides to collect all mail from the board of directors, and then forward those to a newspaper, how would your management than feel?

    I do appreciate the reluctance of your management. Perhaps you can ask your Veritas (sales) rep to come in and have a session on DA, and outline possible risks of not having that, and the risk of allowing users to search the Journal Archive.

7 Replies

  • Yes, if you enable the "Advanced search" auditing category, then EV will audit the following information about each search:

    • Audit ID
    • Status (success or failure)
    • Date
    • User
    • Archive being searched
    • Query text
    • Number of results
    • What range of results was viewed

    I have attached a spreadsheet with some example audit records for searches.

    Keep in mind that with EV Search, all hierarchical folder browsing activity will show up as a series of searches. That is, when a user browses to a folder and displays its contents, EV audits that as a search for that folder's VaultEntryId. The second record in the example spreadsheet represents such a search.

    You would need to enable the auditing category for each server that handles the search requests. Which server owns the archiving tasks is not relevant.

     

    --Chris

      • GertjanA's avatar
        GertjanA
        Moderator

        Hello,

        There is no documentation available. If you need backing on this statement, you might need to ask your legal/compliance department for assistance, as they should be aware of rules and regulations for your region. In addition, perhaps also the HR department. I do not believe either of these want users to access the journaled data, and be able to search for ANY item from ANYONE. For instance, would you like John Doe to search for all email from and to your CEO? Or perhaps from your manager? Including possible classified information send by email?

        the whole idea of having a Journal archive (i.e. Journaled email) is to be able to deliver evidence in a case (be it officially legal, be it internal research) without having evidence tampered with. If you have not secured the Journal Archive well enough, there migth be a risk that information is tampered with. If a user (as mentioned above) holds a grudge (if that is the word), and decides to collect all mail from the board of directors, and then forward those to a newspaper, how would your management than feel?

        I do appreciate the reluctance of your management. Perhaps you can ask your Veritas (sales) rep to come in and have a session on DA, and outline possible risks of not having that, and the risk of allowing users to search the Journal Archive.

  • Hi,

    Why would you give your users access to the Journal Archive(s)?

    That is imho against normal practice, in regards to compliancy and possibly regulatory rules..

    • ashks2014's avatar
      ashks2014
      Level 5

      Hi Gertjan,

      I have tried to raise this point with my management who requested this to no avail. Do you have any relevant links from Veritas or evidence that can help persuade them against this?

      They weren't prepared to pay for discovery accellerator :-(