The SiteMinder Policy Server is configured by default to write audit logs to a text file.
However, the amount of data that is written to a text file by default is less than that which is written to an ODBC Audit Store Database.
Default Audit Fields in the "smaccess.log" file:
EventHostnameTimeClientIpUserNameAgentNameActionResourceSessionIdReasonStatusMsg
Default Audit Fields in an ODBC Audit Store Database:
sm_timestampsm_categoryidsm_eventidsm_hostnamesm_sessionidsm_usernamesm_agentnamesm_realmnamesm_realmoidsm_clientipsm_domainoidsm_authdirnamesm_authdirserversm_authdirnamespacesm_resourcesm_actionsm_statussm_reasonsm_transactionidsm_domainnamesm_impersonatornamesm_impersonatordirnamesm_assertion_idsm_assertion_issueridsm_assertion_destinationurlsm_assertion_statuscodesm_assertion_NotOnBeforesm_assertion_notonoraftersm_assertion_sess_starttimesm_assertion_sess_notonoraftersm_assertion_authcontextsm_assertion_versionidsm_assertion_claimssm_application_namesm_tenant_namesm_authentication_methodsm_devicehashsm_deviceidsm_userrefid
The amount of audit data written to a text file can be configured using "Enable Enhance Tracing" registry key in the SiteMinder Policy Server Registry (1)(2).
HKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\ReportsNAME: Enable Enhance TracingTYPE=DWORDVALUE: <0|1|2|3|4>0 – Disables enhanced auditing1 – Enables enhanced auditing2 – Logs assertion attributes3 – Logs assertion attributes and the authentication method that authenticates a user accesing a resource.4 – Logs assertion attributes, the authentication method and Enhanced Session Assurance with DeviceDNA™ information<Install_Dir>/siteminder/registry/sm.registryHKEY_LOCAL_MACHINE\SOFTWARE\Netegrity\SiteMinder\CurrentVersion\ReportsNAME: Enable Enhance TracingTYPE= REG_DWORDVALUE: <0|1|2|3|4>0 – Disables enhanced auditing1 – Enables enhanced auditing2 – Logs assertion attributes3 – Logs assertion attributes and the authentication method that authenticates a user accesing a resource.4 – Logs assertion attributes, the authentication method and Enhanced Session Assurance with DeviceDNA™ informationEnable Enhance Tracing= 1; REG_DWORD