Audit log of the User access and permissions

Hi All,
We need to have the Audit trail of the user access and permission. Meaning Changes to user access rights will be logged.
This should include:
Current Access Rights (including Date the access was given),
Group membership (including Date the access was given),
Previous Access Rights (including Date the access was given and revoked).
Can we reuse any out of the box functionality of CQ. Does anybody having any pointer to this?
Thanks,
Debasis

Hi PChamoun,
At the outset thanks a lot for the clue. I am very new to CQ. Could you please guide me like, what are the API required to track the rep:policy node changes. Even if workflow will be started after any change to rep:policy but how I will be able to get the information of what change happened.
Thanks,
Debasis

Similar Messages

  • Trigger Audit report whenever the user access the report.

    Hi BOBJ Experts,
    I have a requirement to Email a report whenever a particular user access the BOBJ report. I checked the event based scheduling but no luck. Can anyone help me in this regards.
    Thank You,
    Srinadha Reddy Y.

    Hi PChamoun,
    At the outset thanks a lot for the clue. I am very new to CQ. Could you please guide me like, what are the API required to track the rep:policy node changes. Even if workflow will be started after any change to rep:policy but how I will be able to get the information of what change happened.
    Thanks,
    Debasis

  • Log the user Access to a Channel

    It's possible to log the access to a channel with the system log facility or a simple file when an user click in the desktop link... the link can be an external URL.
    The log must have the user id and the name of the URL for tracking user action in the desktop.
    It's possible using the Rewriter Rules and Rulesets to perfome this?
    If it's impossible we're the better solution?
    Obsiously it's possible to redirect all the channel link of the desktop in a new servelets o jsp page that provides this functionality and log the access but I think there is not the better solution...
    Thank for the help
    Best Regards
    Fausto

    Hi Fausto,
    Of course there are several cool tricks ;-)
    - Your "JS trick with post " will refresh the page - no good...
    (Also what if you log several channels etc.... )
    - For reporting I actually used "JS hidden image" trick.
    Note: You will loose the browser handle from logging jsp
    - "One Pixel Frame" is good only if you need to have a browser handle.
    For example on click e.g. TabSwitch you can show immediate statistics
    (e.g. how many time user spend with this channel and how much he has to pay!)
    PS: I am actually done with the reporting tool.
    Send me a mail if you wanna see it.
    Cheers,
    Alex :-)

  • The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError) Log on failed. Ensure the user name and password are correct. (rsLogonFailed) The user name or password is incorrect

    I am able to run the report fine in BIDS in the preview window, and it deployes fine.  When it goes to view the report in the browser, I get the following error.  There is no domain, I am using a standalone computer with SQL Server and SSRS on
    this one machine.
    Can anyone point to where I might configure the permission it is looking for?  thanks!  Steven
    The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError)
    Log on failed. Ensure the user name and password are correct. (rsLogonFailed)
    The user name or password is incorrect
    Steven DeSalvo

    Hi StevenDE2012,
    Based on the error message "The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError)", it seems that the Unattended Execution Account settings in Reporting Services
    Configuration is not correct.
    Reporting Services provides a special account that is used for unattended report processing and for sending connection requests across the network. Unattended report processing refers to any report execution process that is triggered by an event rather than
    a user request. The report server uses the unattended report processing account to log on to the computer that hosts the external data source. This account is necessary because the credentials of the Report Server service account are never used to connect
    to other computers. To configure the account, please refer to the following steps:
    Start the Reporting Services Configuration tool and connect to the report server instance you want to configure.
    On the Execution Account page, select Specify an execution account.
    Type the account and password, retype the password, and then click Apply.
    In addition, please verify you have access to the Report Server database by following steps:
    Go to SQL Server Reporting Services Configuration Manager, make sure the configuration is correct.
    Go to Database, Verify that you can connect to the database.
    Make sure you are granted public and RSExecRole roles.
    Reference:
    Configure the Unattended Execution Account
    Configure a Report Server Database Connection
    If the problem is unresolved, i would appreciate it if you could give us detailed error log, it will help us move more quickly toward a solution.
    Thanks,
    Wendy Fu

  • The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError) Log on failed. Ensure the user name and password are correct. (rsLogonFailed) Logon failure: unknown user name or bad

    The report server has encountered a configuration error. Logon failed for the unattended execution account. (rsServerConfigurationError)
    Log on failed. Ensure the user name and password are correct. (rsLogonFailed)
    Logon failure: unknown user name or bad password 
    am using Windows integrated security,version of my sql server 2008R2
    I have go throgh the different articuls, they have given different answers,
    So any one give me the  exact soluction for this problem,
    Using service account then i will get the soluction or what?
    pls help me out it is urgent based.
    Regards
    Thanks!

    Hi Ychinnari,
    I have tested on my local environment and can reproduce the issue, as
    Vaishu00547 mentioned that the issue can be caused by the Execution Account you have configured in the Reporting Services Configuration Manager is not correct, Please update the Username and Password and restart the reporting services.
    Please also find more details information about when to use the execution account, if possible,please also not specify this account:
    This account is used under special circumstances when other sources of credentials are not available:
    When the report server connects to a data source that does not require credentials. Examples of data sources that might not require credentials include XML documents and some client-side database applications.
    When the report server connects to another server to retrieve external image files or other resources that are referenced in a report.
    Execution Account (SSRS Native Mode)
    If you still have any problem, please feel free to ask.
    Regards
    Vicky Liu
    Vicky Liu
    TechNet Community Support

  • Hi, I have a PPC Running OSX 10.5.4 and I want to delete the User "Guest"and "Shared"Folders on my HD, they won't let me change the permissions and I keep getting errors that say the permissions should be 0 and are 501 and having files i can't delete that

    Hi, I have a PPC Running OSX 10.5.4 and I want to delete the User "Guest"and "Shared"Folders on my HD, they won't let me change the permissions and I keep getting errors that say the permissions should be 0 and are 501 and having files i can't delete that go on and on ad infinitum... I think it's a virus or a corruption? Can anyone tell me or help me and let me know what I'm dealing with here or wether I'm mistaken and should leave it alone?
    I'd appreciate it.
    Thanks,
    Matt

    mattmakesvidiots wrote:
    Hi, I have a PPC Running OSX 10.5.4 and I want to delete the User "Guest"and "Shared"Folders on my HD
    Why do you want to delete those?  What have you done so far to do that?
    I doubt that Mac has a virus.  On the other hand, your attempts to deleted those folders may have caused corruption.
    Two other comments:
    1) Is there a reason that Mac hasn't been updated to OS X 10.5.8?
    2) You've been misled by the poor field labeling on this Web site into trying to type your entire post into the "subject" field.  In the future, just put a short summary of your post into that field.

  • Problems with access and permissions

    Hi,
    I installed the 10.5.3 update, well software update installed 10.5.3, and it managed to completely bugger up my system. I could not boot up, nor could i safe boot. A verbose boot revealed it was stuck in some form of loop, loading something, which then quit due to an error and it continued to try and load it. I resorted to reinstalling os x with an archive and install due to my external disk breaking i could not restore from a time machine back up. BAsically the install managed to go wrong, and i ended up having to reinstall again. When i finally got to my desktop none of my settings had been carried over and they were in a previous system folder. I fired up migration assistant to copy it over because of the access and permissions stopping me from doing it manually. Migration assistant told me i needed a huge amount of terabytes to perform the migration! So i tried to do it manually.
    Basically all my stuff is in my home folder but none of it is set to my new user name, all the rights are set to _Unknown which is, im guessing, my old user account. Is there any way to mass set the access and permissions to my new account, including that of all the subfolders and contents?
    Any help would be appreciated, im at the end of my tether here! This is the 3rd time ive had problems with a leopard upgrade. Why does software update always fail to perform an upgrade?

    From your account, open /Applications/Utilities/Terminal, and copy the blue text in, and press enter (you'll have to provide your admin password, which you won't see. That's normal.)
    sudo chown -R `id -u`:`id -g` ~
    After that finishes, the prompt with Computername:~ username$ will come back, and you can quit Terminal.
    To be sure, you should log out and log in again.
    Good luck!

  • SQLException in the audit log for the Message Display Tool

    Hi
    I´m newbie in PI Technology, and i have some issues when i try to do the next.
    This is the scenario:
    I need to communicate two systems, for one side i have SAP, and for the other side i have ADI (legal system) so, i use PI to do this (the communication), PI receive the data from SAP by means abap proxy, until this everything is correct, then i do the mapping of the data and i send a message to ADI (with the SAP XI Runtime Workbench) by means JDBC adapter, if i check the sended message with "Message Display Tool" show that the message was sent (status "Delivered") but if i check the received messages option, in the audit log displays the five next errors:
    Error: Could not execute statement for table/stored proc. "FADIA4" (structure "StatementFADIA4") due to java.sql.SQLException: FADIA4 in FILEMET not valid for operation.
    Error: JDBC Message processing failed, due to Error processing request in sax parser: Error when executing statement for table/stored proc. 'FADIA4' (structure 'StatementFADIA4'): java.sql.SQLException: FADIA4 in FILEMET not valid for operation.
    Error: MP: exception caught with cause com.sap.engine.interfaces.messaging.api.exception.MessagingException: Error processing request in sax parser: Error when executing statement for table/stored proc. 'FADIA4' (structure 'StatementFADIA4'): java.sql.SQLException: FADIA4 in FILEMET not valid for operation.
    Error: Adapter Framework caught exception: null
    Error: Delivering the message to the application using connection JDBC_http://sap.com/xi/XI/System failed, due to: com.sap.engine.interfaces.messaging.api.exception.MessagingException: Error processing request in sax parser: Error when executing statement for table/stored proc. 'FADIA4' (structure 'StatementFADIA4'): java.sql.SQLException: FADIA4 in FILEMET not valid for operation..
    if there are somebody that maybe could know what is the problem?, could the problem be the side of the legal system?, because inside of PI when i do the Test Configuration in the Integration Directory, the end of the test is successful.
    Any comment is well received!!
    Thanks,
    Vicman
    P.D. sometimes the error is: java.sql.SQLException: Token ) was not valid. Valid tokens: DAY PATH YEAR LABEL MONTH OPTION RESULT CONNECTION TRANSACTION.
    what does it means?

    Hi Pooja,
    thanks for you quickly response!
    XML sended:
    <?xml version="1.0" encoding="UTF-8"?>
    <ns0:MT_PgDocVentaECC_req xmlns:ns0="http://gmodelo.com/ECC/enviarCobranza">
       <DT_DatosDeControl>
          <MIDDLEWARE_ID/>
          <QUICK_ID/>
          <INTERFACE_NAME/>
          <MESSAGE_ID/>
          <LOG_ID/>
          <USER_ID/>
          <SOURCE_SYSTEM/>
          <TARGET_SYSTEM/>
       </DT_DatosDeControl>
       <DT_PagoDocVentaECC>
          <VKORG>TVKO</VKORG>
          <VKBUR>TVBUR</VKBUR>
          <VKBUR1>TVBUR</VKBUR1>
          <ROUTE>TVRO</ROUTE>
          <ROUTE1>TVRO</ROUTE1>
          <BLART>Q</BLART>
          <BELNR>100</BELNR>
          <WRBTR>200</WRBTR>
          <LFART>100</LFART>
          <VBELN>100</VBELN>
       </DT_PagoDocVentaECC>
    </ns0:MT_PgDocVentaECC_req>
    this is the XML received:
    <?xml version="1.0" encoding="UTF-8"?>
    <ns1:MT_PgDocVentaADI_req xmlns:ns1="http://gmodelo.com/ADI/recibirCobranza">
    <StatementFADIA7>
    <FADIA7action="INSERT">
    <Table>FADIA7</Table>
    <Access>
    <NUMCIA>123</NUMCIA>
    <NUMALM>234</NUMALM>
    <SUBALM>300</SUBALM>
    <CVETOP>16</CVETOP>
    <FOLOPV>22</FOLOPV>
    <SECOVA></SECOVA>
    <IMPOVA>200</IMPOVA>
    <ALMOVA>5678</ALMOVA>
    <SUBOVA>21</SUBOVA>
    <TOPOVA>21</TOPOVA>
    <FOPOVA>41</FOPOVA>
    <FECOVA>100</FECOVA>
    <STSOVA> </STSOVA>
    </Access>
    </FADIA7></StatementFADIA7>
    </ns1:MT_PgDocVentaADI_req>
    what do you think about it?, anything wrong?

  • How do i get the user id and responsibility id

    Hi
    I have coded my own jsp page and being given function in Oracle Apps in order to open my jsp page.
    Its opening properly.
    But i need to capture the user id and responsibility id of the person who logged in. I created the function in a particular responsibility only. I need to know the responsibility id and user id.
    I am using oracle 11.5.10. I know in previous versions with FWAppsContext. But in 11.5.10, i am not able to see the methods like getUserId() and getRespId() in FWAppsContext class.
    Please help me out, its very urgent.

    You can get the webAppsContext from your custom jsp using the following code.
    import oracle.apps.fnd.common.WebAppsContext;
    Import oracle.apps.fnd.common.WebRequestUtil;
    WebAppsContext webAppsContext = WebRequestUtil.validateContext(request, response);
    getUserId and getRespId are public methods which can be accessed through webAppsContext.

  • Way to allow the user access to the saved lists of this Z report

    We have a Z report that we want to run at midnight each Sunday and then view the output/layout first thing Monday morning. We can schedule the report to run but it appears that the only way we can save the output as a 'file' for later viewing is by using the "Save with ID" option, which puts the output into a SAP 'saved list'.
    The problem with this is that it doesn't appear to be possible to access that list from the Z-report - it would appear that you have to go into SQ01 and use the 'saved list' button. This means giving the Z- report user access to SQ01 as well as Z-report, which, for security (SOD) reasons we don't want to do.
    We can run the report in foreground with the output option "File store" and save the output as a file to a specified location,. But this option doesn't appear to be available when the report is scheduled as a background job. If this is done, the background job runs but there's no output anywhere, as far as we can tell.
    So what want is to run the report in background but with the output option 'File store' or equivalent (i.e. an output stored somewhere that the report user can view). Is this not possible, or have we missed something in setting up the report run?
    Or is there a way to allow the user access to the saved lists of this Z report without giving them T-code SQ01?
    Thanks

    Hi !
    I just wonder if the answer from Varishtb below did solve your propblem.
    I have exactly the same problem as you. I also want to be able to look at the saved list without using the sq01.
    If you solved it I will be grateful to get the solution.
    regards Lars
    answer:
    You can call the infoset query directly from a transaction code. There's
    no need to copy it as a 'Z-report' (or as a custom report). In fact,
    everytime you're copying an infoset query to a report, you're calling
    for problems the next time you face an upgrade. (That is because SAP
    changes the internal logic used to handle the infosets queries from
    version to version)
    We're using some infoset queries and they work fine this way.

  • When Logging in the user gets "The ID you entered was not found"

    I have UCCX v8.  All users can log in fine.  However, I have created a new user and they are getting "The ID you entered was not found".
    1.  The user was created in CUCM, extension made available to UCCX, and device associated to RMuser account
    2.  The user shows up in resoureces and I can assign them to a queue
    3.  The User shows up in Tools/User Management/User List
    4.  You can assign the user to a Team
    5.  The User DOES NOT show up in the Supervisor
    I have tried unassociating and re associating the user's device with the RM User account.
    I have tried restarting the User Desktop Synchronisation Service.
    I have deleted the User acount and recreated it
    I have reset the passsword
    When the user was deleted they showed up under inactive users in UCCX.  I deleted the user from here, recreated the user in CUCM, and the new user showed un in resources.  This suggests that synchonisation is workinhg.
    Anyone have any other ideas that I can try?

    You are not mentioned where you are trying to login is that CAD or Cisco supervisor desktop.
    I also got the same error while I tried to login as Supervisor but the same time I am able to login CAD without any issue.
    When I checked the user in UCCX it's not added as Supervisor so once I did I am able to login
    I did this in UCCX 8.0.2
    Hope this will help

  • APO Security to control the users access

    Hi,
    Is there any possibility to control the users access by controlling through selection ID's or does it possible through any of the product lines (Characteristics)?
    My requirement is I have to control all the APO DP users in various levels of Product lines and the access has to be granted at specific product level. Right now I am trying do through selection ids, but I am looking for more effective way.
    Please help me with your views.
    Thank you in advance!
    Jegan

    Hi Jegan,
                  There are so many security objects in DP that you can try out and see if they meet your requirement.
    The way I understand your issue is to restrict user by certain products or BW characteristics.
    To control by Products, try the object  C_APO_PROD with activity APO_PROD (Product Identifier). You can select specific products here for each role and restrict by either display, change, execute, delete etc.
    If you want to restrict by BI characteristics, try  object S_RS_AUTH.
    Be careful with this as you are selecting BI objects, the system restricts them even if they are remote part of your work.
    If you have to restrict by specific product levels like all product lines, I am not sure how to do it but you can certainly try searching based on keyword "PROD".
    Please let us know if you discover something useful.

  • After Time Machine backs up my file vault files (after logging out), when I next log into the user account it beachballs permanently during log in.

    After Time Machine backs up my file vault files (after logging out), when I next log into the user account it beachballs permanently during log in.  The backup was successful, as I had to restore after this issue last time.  Hard resetting doesn't resolve the issue.  Is there a Time Machine setting that I should be aware of?
    I have 2011 13" MBP, 10.6.8 and use an external hard drive connected via USB for my Time Machine backups.
    Thanks

    I was able to get it to work.  Thanks for your help.  It's unfortunate the two applications do not work well together.  This is what I did:
    1) Safe boot and logged into the affected user (since the whole issue damaged the account's system settings).
    2) Turned off File Vault in System Preferences. I needed to make some space on the hard drive first since apparently the total free space on the hard drive has to equal or exceed the amount of data currently in the file vault.  I deleted some files and moved others to the Admin account.  This whole process took awhile.
    3) Finally, just restarted and logged in.  The next time machine backup seems to be a significant backup, I assume because it's backing up the user account in a different way now that File Vault is turned off.
    Thanks again!

  • Unable to log into the user management administration web console

    Can someone tell how resolve my ablity to log into the user management administration web console? I can't log into SAP Netweaver Admin,  User managment, and Webdynpro content Administrator and Web Dynpro Consol. But able active j2ee engine sample? Is there some that I need activate to allow me log in? 
    http://localhost:50000/logon/logonServlet?redirectURL=%2Fuseradmin%2FuserAdminServlet%3FgotoDefaultPage%3D.

    Hi,
    I had this problem also. For me it worked to log on to the SLD and then I was able to log on to the other applications like Useradmin and NWA.
    The SLD is usually available at <a href="http://localhost:50000/sld">http://localhost:50000/sld</a>.
    Regards,
    Sebastian

  • I am trying to deauthorize my audible account.  It says the user name and/or password are incorrect after I had just deauthorized the computer using the same user name and password.  They should be different correct?

    I am trying to deauthorize my audible account.  It says the user name and/or password are incorrect after I had just deauthorized the computer using the same user name and password and logging in to post this.  They should be the same password correct?

    Deauthorize Audible Account... always appears as a menu selection, even if you deauthorized Audible or never even had an account.
    Audible is a different account from iTunes and does not require the same username / password.

Maybe you are looking for