000030565 - The RSA Security Analytics Server is not capturing the value for queryString in the audit logs

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 22, 2017
Version 3Show Document
  • View in full screen mode

Article Content

Article Number000030565
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Security Analytics Server
RSA Version/Condition: 10.5.x, 10.6.0.0
Platform: CentOS
O/S Version: EL6
IssueWhen changing the file contents of a Security Analytics service, the Security Analytics server audit logs do not indicate which file the user changed.
When looking at the audit logs, the value for queryString is not being captured by the Security Analytics Server, as shown below.
User-added image
ResolutionThis issue is currently being investigated by the Engineering team in order for it to be resolved in a future release.
If you have any additional questions or concerns regarding the issue, contact RSA Support and quote this article number for further assistance.

Attachments

    Outcomes