Description

This article provides us information on whether audit logs can be forwarded to syslog server or not

Solution

There is no way to send audit logs to the syslog server from SWA. However, you can view the audit logs on SWA by downloading the diagnostic package (System > Diagnostics Package). Look for a file named “audit.log” in the diagnostics-package\opt\splunk\var\log\splunk directory. This package will capture all user activities, including system users.

 

Modification History

2025-06-23 : Article Created