The Monitoring dashboard in Cloud Control Center gives visibility into all system activity and administrative events that occur in Cloud Control Center and Elisity Infrastructure. From user login, to Policy Group modifications, to Policy deployments or deletions, this is where you can find a log of all activity in Cloud Control Center. This includes system activity and events, as well as infrastructure alerts. See the list below for a categorical view of all monitoring views available.
Audit logs show changes made by any user in Cloud Control Center such as configuration changes, policy modifications, device creation, modification, and purging actions, and so on. Audit logs also contain login events for users which includes the user's source IP address. This provides customers with industry standard, exportable audit logs required by most compliance regulations. Each record identifies the Category, Level, Action, Username, User Role, and Timestamp, and the Details column can be expanded to show the full record.
Events shows system actions and events that occurred that were not necessarily the result of user configuration such as device Policy Group assignments, Virtual Edge registrations, and so on. Events records many of the events that are also found in Activity Logs and Events.
Activity Logs shows all infrastructure related activity such as VE/VEN onboarding, decommissioning, and recommissioning. This corresponds directly with the Activity column in the notifications pane.
Alerts provides status alerting of Elisity infrastructure such as Virtual Edge and Virtual Edge Node Online, Offline, Degraded, and Healthy status changes. The Alerts view enables quick and easy monitoring of the status of your Elisity Infrastructure. As mentioned, these alerts are also recorded in the Events view. This corresponds directly with the Alerts column in the notifications pane.
Agent Events shows activity reported by the Elisity Active Directory (AD) Agents running on your network. The Source column identifies the agent process that produced each record, which makes this the view to check when confirming that Monitoring records are being forwarded to a destination outside Cloud Control Center.
External Monitors is where you configure the forwarding of Monitoring records to a destination outside Cloud Control Center, such as a syslog server on your own network or a security information and event management (SIEM) platform. Monitors are added from Monitoring > External Monitors. Records continue to be written to the Monitoring views described above whether or not forwarding is configured, so the data remains available in Cloud Control Center regardless of the external destination. For the syslog destination, see Configure Syslog Forwarding for CCC Monitoring Events.
Custom filtering can be applied and saved for each of these views, giving Administrators the ability to export filtered (or unfiltered) data for auditing or compliance checks. Logs can also be filtered by the last hour, 24 hours, week or month - layered with additional filters - to filter down to specific types of events that occurred within a given time frame.
Monitoring data can be exported with or without these filters by clicking on Export Data and selecting the appropriate option - Export Filtered Data or Export All Data. Monitoring data contains up to 10,000 events which are all exported, depending on the filter applied.
Event history for an individual device is available from the Device Details view. Navigate to IdentityGraph > Devices, open the device, and select the Device Events tab.
The Device Events tab groups records by date and lists the Time, Event Class, and Description of each event. Expanding a row shows the full event record. This gives administrators a single, chronological view of a device's activity - when it attached and detached, which Policy Group it was associated with, and which connector attributes enriched it - without leaving the device.
External Policy Logging
Security Profiles in Elisity include the ability to log policy events. This feature allows you to gain deeper insights into network activity and is particularly useful for monitoring and analyzing security-related events. The sections below describe how to enable logging in Security Profiles and provide important information about its usage.
Policy Logging is a global setting that cannot be turned off once enabled. To enable Policy Logging, navigate to Policy > Policy Settings > Advanced and turn on the Enable Policy Logging toggle in the Policy Logging card.
Per-Rule Logging
You can enable logging on a per-rule basis within Security Profiles that can be sent to a syslog server for the purpose of monitoring policy enforcement interactions for any security profile you choose. This means that you can choose to log specific rules while leaving others unaffected. This level of granularity allows you to focus on the rules that are most critical for your security monitoring needs. Note that by enabling logging for a Security Profile, logging will be enabled for every policy that uses this specific Security Profile.
To enable logging for specific rules:
- Access the Security Profile: Navigate to Policy > Security Profiles and open the Security Profile you want to modify.
- Edit the Rule: Locate the rule you want to enable logging for and click the edit icon in the Actions column to edit its settings.
- Enable Logging: In the rule settings, you will find a Log option. Select Enable Log to enable syslog generation for that specific rule.
- Save Changes: Make sure to save your changes to apply the logging configuration to the rule.
Final Policy Action Logging
In addition to per-rule logging, you can enable logging on the Final Policy Action. This allows you to capture logs about the ultimate outcome of the Final Policy Action. You can use this feature to ensure that you have a record of what happens to traffic that doesn't match any specific rule. This is enabled per policy rather than at the security profile.
To enable logging for the Final Policy Action on a policy:
- Access the Policy: Navigate to Policy > Matrix, switch to the Table view, and click the policy you want to modify to open the Edit Policy panel.
- Enable Logging: Below the Security Profile selector, select Enable Log for Final Policy Action.
- Save Changes: Click Save Changes to activate logging for the Final Policy Action.
Viewing Policy Logging Status
Logging status is available in both the Security Profiles dashboard and the Policy Records table, allowing users to quickly see the logging status and filter Security Profiles and policies by this attribute.
Security Profiles Dashboard
Logging status (Enabled or Disabled) can be viewed on the Policy > Security Profiles page by using the Policy Logging column. This column, as all other columns, can be moved, enabled, disabled, and filtered.
Policy Records
Logging status (Enabled or Disabled) can be viewed per policy by navigating to Policy > Matrix and switching to the Table view. The Policy Records table lists each policy with its Final Policy Action, Status, and Logging value. This column, as all other columns, can be moved, enabled, disabled, and filtered.
Performance Considerations
Policy Logging generates syslog messages from the Virtual Edge Node. It is a CPU-intensive operation and may impact switch performance, so monitor Virtual Edge Node utilization when logging is enabled at high volume and consider limiting logging to the rules and policies you need to observe.
Note: Default Policy
Logging for the Default Policy is not required and is not impacted by the settings mentioned above. The Default Policy is designed to handle traffic that doesn't match any Policy Group in Cloud Control Center.