Page tree


In This Document 



Have a suggestion for the Armor Knowledge Base? Send a message to kb@armor.com.




You can use the Log & Data Management screen to:

  • View collected logs in the Search section
  • View the status of the logging subagent in the Sources section

By default, Armor collects and retains the following log types for 30 days:

CentOS/RHEL
Ubuntu/Debian
Windows

/var/log/secure

/var/log/messages

/var/log/audit.log

/var/log/audit/audit.log

/var/log/yum.log

/var/log/auth.log

/var/log/syslog

System Event Log

Security Event Log