IBM Endpoint Manager, Version 9.2

Component Log Files

These are the log files of the BigFix components:

Server Audit log: The server keeps an audit log and traces the following types of audit events:
AuditStream() << "approver \"" << checkResult.user 
<< "\" approved an activity performed by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was made a reader for custom site \"" 
<< parameters.siteName.GetString() << "\"" << "by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was removed as a reader from custom site \"" 
<< parameters.siteName.GetString() << "\"" << "by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was made a writer for custom site \"" 
<< parameters.siteName.GetString() << "\"" << "by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was removed as a writer from custom site \"" 
<< parameters.siteName.GetString() << "\"" << "by " << "user "{name}" ({id})";
AuditStream() << "role "{name}"" << " was created by " << "user "{name}" ({id})";
AuditStream() << "role "{name}"" << " was deleted by " << "user "{name}" ({id})";
AuditStream() << "role "{name}"" << " has been given " << ( it->second 
== UserRoleSitePrivileges::SiteWriter ? "write" : it->second == UserRoleSitePrivileges:
:SiteReader ? "read" : "ownership" ) << " privileges on " << SiteAuditText( it->first ) 
<< " by " << UserAuditText( user );
AuditStream() << "user "{name}" ({id})" << " has been added to " << "role "{name}"" << 
" by " << "user "{name}" ({id})";
AuditStream() << "ldap group "{name}" (DN={dn})" << " has been added to " << "role 
"{name}"";
AuditStream() << "site {site}" << " removed from " << "role "{name}"" << " by " << 
"user "{name}" ({id})";
AuditStream() << "site {site}" << " added to " << "role "{name}"" << " by " << "user 
"{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " added to " << "role "{name}"" << " by " << 
"user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " removed from " << "role "{name}"" << 

" by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was assigned to " << "role "{name}"" << 
" by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " was removed from " << "role "{name}"" <<
" by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " privileges updated by " << "user "{name}
" ({id})" << ": " 
<< PrivilegesAuditText( iface.db, userInfo, isMasterOperator, canCreateCustomContent, 
showOtherUsersActions, unmanagedAssetPrivilege, loginPermission, approverRoleID );
AuditStream() << "ldap user \"{name}\" (DN={dn})" << " created by " << "user "{name}" 
({id})";
AuditStream() << "user "{name}" ({id})" << " password changed by " << "user "{name}" 
({id})";
AuditStream() << "user "{name}" ({id})" << " changed their own password";
AuditStream() << "user "{name}" ({id})" << " was removed by " << "user "{name}" ({id})";
AuditStream() << "user "{name}" ({id})" << " management rights updated by " << "user 
"{name}" ({id})";
AuditStream() << oldUserAuditText << " converted to ldap user " << "ldap user \"{name}\
" (DN={dn})" << " by " << initiator;
AuditStream() << "role "{name}"" << " was modified by " << "user "{name}" ({id})" << 
": " << PrivilegesAuditText( iface.db, role.UserRolePrivileges() );
AuditStream() << "user "{name}" ({id})" << " created by " << "user "{name}" ({id})
" << ": "
AuditStream() << "ldap user \"{name}\" (DN={dn})" << " created based on membership 
of role(s): " << roleNames.Ref();
These are the default locations of the audit logs for each operating system:
  • Windows: %PROGRAM FILES%\BigFix Enterprise\BES Server\server_audit.log
  • Linux: /var/opt/BESServer/server_audit.log
BES Root Server log:
  • Windows: C:\Program Files (x86)\BigFix Enterprise\BES Server\BESRelay.log
  • Linux: /var/log/BESRelay.log

Gather log: Only for Windows operating systems http://127.0.0.1:52311/cgi-bin/bfenterprise/BESGatherMirrorNew.exe

FillDB log:
  • Windows: C:\Program Files (x86)\BigFix Enterprise\BES Server\FillDBData\FillDB.log
  • Linux: /var/opt/BESServer/FillDBData/FillDB.log
GatherDB log:
  • Windows: C:\Program Files (x86)\BigFix Enterprise\BES Server\GatherDBData\GatherDB.log
  • Linux: /var/opt/BESServer/GatherDBData/GatherDB.log
Relay log:
  • Windows: C:\Program Files (x86)\BigFix Enterprise\BES Relay\logfile.txt
  • Linux: /var/log/BESRelay.log
Client log: The client records its current activity into a log file with the current date as the file name in the format [year][month][day].log. If an active log reaches 512K in size it will be moved to a backup (.bkg) file and a new log will be started for the current day. If the log reaches 512K again the backup will overwrite the existing backup. Both the active and backup logs will be deleted after ten days. These are the default locations of the BigFix client logs for each operating system:
  • Windows clients: C:\Program Files\BigFix Enterprise\BES Client\__BESData\__Global\Logs
  • UNIX, Linux clients: /var/opt/BESClient/__BESData/__Global/Logs
  • Mac clients: /Library/Application Support/Bigfix/BES Agent/__BESData/__Global/Logs

The directory of the BES Server Plugin Service log is C:\Program Files\BigFix Enterprise\BES Server\Applications\Logs.



Feedback