View and Track BeyondTrust Vault Activity in PRA
Reporting is available to track account and user activity. Specifically, report administrators and users can view and track information about the following:
- Account creations and deletions
- Credential check-ins and check-outs
- Personal credential used
- Password rotations and changes
To run Vault reports:
- From the /login interface, navigate to Reports > Vault. The following report parameters are available for selection:
- Date Range: View all events within a specific date range.
- Account: View all events associated with a specific account.
- Performed By: View all events involving a specific user, API account, or the System.
- Check the Include Windows services events option to include events relating to service account rotation.
- Make your selections, and then click Show Report. The report provides the following information:
- Timestamp: The date and time the event occurred.
- Account: The account name used with the event.
- Event Type: The type of event which occurred, such as a credentials checked in or checked out, or password rotated.
- Performed By: The user who triggered the event.
- Data: Relevant system information message, for example if a password rotation failed, the error message is indicated.
- Endpoint: The system where the event the event occurred.
- Data Service: This column appears in the reporting results only when the Include Windows services events option is enabled. Any errors that occur with service account rotation events are shown in this column.
Events are logged in order to generate reports, and these logs are saved for 90 days.
Non-administrative users may experience a more limited /login user experience, depending on the access granted to them by their administrator. For example, a Vault user with limited permissions may potentially see only the Accounts, Vault, and Reports > Vault tabs.
If a user has been anonymized in an effort to follow compliance standards, the Vault Account Activity report may display pseudonyms for user data or may indicate that information has been deleted. To learn more about data anonymization and deletion for compliance efforts, please see Compliance: Anonymize Data to Meet Compliance Standards.
For more information, please see Vault: Report on Vault Account and User Activity.