Audit
3 tutorials in this category.
05
How to Use Audit Logs to Track Package Consumption and Policy Changes
Navigate the audit page, filter events by actor/action/date, and build an audit trail for compliance reviews.
06
How to Send Violations to Splunk HEC, Microsoft Sentinel, or IBM QRadar
Wire Chainsaw's audit and violation streams into your existing SIEM. Walk through the three exporter types — Splunk HEC JSON, Sentinel CEF over syslog, QRadar CEF over syslog — and the durable replay semantics that mean a SIEM outage doesn't lose events.
06
How to Enable Monitoring for a Single Policy
Use per-policy Monitor mode to record audit-only matches on one policy without disabling enforcement on the rest of your policy stack.