Audit log access, user roles, and alert mechanisms in Adobe Experience Manager Managed Services
This article explains the audit logs available in Adobe Experience Manager (AEM) Managed Services, identifies the user roles that can access them, and describes the alert mechanisms used to monitor audit log access and related activities.
Description description
Environment
Adobe Experience Manager (AEM) Managed Services (all versions)
Issue/Symptoms
- Organizations using Adobe Experience Manager (AEM) Managed Services for Information Risk Management (IRM) activities need to understand how audit logs are managed, who can access them, and how alerts for suspicious activities are handled for compliance and process transparency.
- Need to identify which user roles can access various audit logs within AEM Managed Services.
- Requirement to document alert mechanisms for suspicious or unauthorized activities related to audit log access.
- Need for evidence or records showing that audit log reviews have been performed, including which users or groups have access and how alerts are addressed.
Cause
These requirements arise from IRM policies to ensure that only authorized users can access sensitive logs and that suspicious activities are monitored and documented for compliance.
Resolution resolution
Follow the steps below to resolve the issue.
-
Identify the audit log layers in Adobe Experience Manager (AEM) Managed Services:
- AEM application audit logs: These logs capture actions such as user management and permissions changes. They are typically stored in the AEM application’s log location, such as the
error.logfile accessible through the AEM OSGi console. - Operating system audit logs: These logs track system-level events on the servers hosting AEM. Access to these logs is restricted to authorized personnel.
- Admin Console audit logs: Organization-level logs accessible through the Adobe Admin Console.
- AEM application audit logs: These logs capture actions such as user management and permissions changes. They are typically stored in the AEM application’s log location, such as the
-
Determine access permissions for each log type:
- AEM application audit logs: Only users in the
Administratorsgroup within AEM can access these logs. To view group membership, navigate to Security>Groups from the AEM start page and selectadministrators. - Operating system audit logs: Customer users typically do not have privileges to view these logs. Access is limited to authorized personnel.
- Admin Console audit logs: Only users with the System Administrator or Admin Developer roles can view and download these logs. Standard developers do not have access.
- AEM application audit logs: Only users in the
-
Review alert mechanisms:
- Adobe Managed Services monitors infrastructure for anomalous or malicious activity using internal security controls. Not every legitimate read of an audit log file triggers a customer-visible alert. Alerts for suspicious activities are handled through Adobe’s internal monitoring processes.
-
Gather evidence of audit log reviews:
- Maintain records of audit log reviews, such as screenshots of group membership, access logs, or records showing when reviews were performed and by whom. Customer-accessible evidence is limited to logs and group membership information available through the AEM interface and Admin Console.
-
Review the Adobe documentation on auditing user management operations for additional information about auditing user operations in AEM.