SecurityWorkCentre 6400 Multifunction PrinterSystem Administrator Guide79Audit LogWhen the Audit Log feature is enabled, the printer begins recording events that happen on the printer.You can download the Audit Log as a tab-delimited text file, and review it to find security breaches andassess the printer’s security.Enabling Audit LogNotes:• Secure HTTP (SSL) must be enabled before you can enable Audit Log. For details, seeEnabling Secure HTTP (SSL) on page 65.• If your printer is locked, you must log in as a system administrator. For details, seeAccessing CentreWare IS on page 17.1. In CentreWare IS, click Properties > Security > Audit Log.2. Click Enabled under Enabling Audit Log on machine.3. Click Apply.Saving an Audit LogNote: If your printer is locked, you must log in as a system administrator. For details, see AccessingCentreWare IS on page 17.1. In CentreWare IS, click Properties > Security > Audit Log.2. Click Save.3. Right-click the Download Log link and save the compressed auditfile.txt.gz file to your computer.4. Extract the Auditfile.txt text file, and open it in a spreadsheet application that can read a tab-delimited text file.Interpreting the Audit LogThe Audit Log is formatted into ten columns• Index: Column 1 lists a unique value that identifies the event.• Date: Column 2 lists the date that the event happened in mm/dd/yy format.• Time: Column 3 lists the time that the event happened in hh:mm:ss format.• Event ID: Column 4 lists the type of event. The number corresponds to a unique description. Fordetails, see Audit Log Event Identification Numbers on page 174.• Event Description: Column 5 lists an abbreviated description of the type of event. For details, seeAudit Log Event Identification Numbers on page 174.Notes:• One audit log entry is recorded for each network destination within a Workflow Scanningscan job.• For Server Fax jobs: One audit log entry is recorded for each Server Fax job.• For Email jobs: One audit log entry is recorded for each SMTP recipient within the job.