
Hello
We have several Domain Groups setup who have access to login to the Web Console, some of which are 'Operators' within IPAM.
Unfortunately this also gives them more permissions than we would like as we just want them to be able to edit the properties of single IP addresses.
Is there a way to log all events within IPAM and have it show who did what?
For example, if someone creates a sub/super net, we need a log to show what they did, when they did it and who did it?
Thanks
Hi noneforit--
I don't believe this kind of "audit trail" is available as of now. I will mark for the PM to log as a feature request.
Thanks!
DH
Hi,
this is functionality is not in the IPAM. Anyway, you may see What we are working on post IPAM 2.0and you can find out that we want to add the User Delegation feature. Does this resolve your problem (you may create more groups/users with different privileges) or you would still need an "audit reporting"?
thanks,
Michal
We basically just want the ability to give certain users/groups permission to edit IP address details only.
We assign our static IP's by marking an IP address as used in IPAM.
The role above Read Only which is Operators is able to do this but they are also able to:
This is more permission than they need so if the roles are not going to be delegated further then we need auditing within IPAM
Thanks
if you would use something like "IPAM - Last 1000 IP History records" in Orion report writer, would it be sufficient for your auditing purposes?
Whilst that does show the changed being made it simply shows 'System' as the username, we need to track who made changes within IPAM
Thanks
if you try to do a change manually there should appear the user name of those who was signed and made this change.
It does indeed :)
Unfortunately it only shows manual IP edits to individual addresses.
I tried to create a test Subnet and Supernet and this was not picked up in the report, can I edit it somehow to pickup when new Super/Sub nets are created?
Thanks :)
you can try to create a new report - select IPAM events type - and then add all required fileds as "user", "event message", "event type" or any other you are interested in.