Data Access Audit

Overview

The Data Access Audit tab provides a detailed log of all actions performed within the Data Access Management module for Amazon S3. It captures every change related to users, roles, permissions, and metadata objects such as buckets, folders, and files, offering complete visibility into access control operations.

Each audit entry logs who made the change, what was modified, when it occurred, and the source of the change. This ensures accurate traceability for compliance, governance, and operational oversight.

Audit data is captured at various levels, including instance, connector, roles, users, policies, and S3 permission entities like buckets and folders.

Instance-Level Audit

  • Date: Timestamp of the action

  • Audit User: The User who performed the action

  • Action: Performed action.

  • Description: Summary of the change

Connector-Level Audit

  • Date: Timestamp of the action

  • Audit User: The User who performed the action

  • Connection Name: Name of the S3 connector involved

  • Action: Performed action

  • Description: Summary of the change

Roles-Level Audit

  • Date: Displays when the role-related action occurred.

  • Role: Shows the name of the role impacted.

  • Audit User: Identifies the user who performed the action.

  • Action: Indicates the type of change made to the role.

  • Source: Specifies the origin system where the change occurred.

  • Description: Provides additional details about the role change.

User-Level Audit

  • Date: Displays when the user-related action occurred.

  • User ID: Shows the identifier of the user involved in the change.

  • Audit User: Identifies who performed the action.

  • Action: Indicates the nature of the change made to the user.

  • Source: Specifies the origin of the change.

  • Description: Describes what was modified for the user.

Policies-Level Audit

  • Date: Timestamp of the policy change

  • Policy: Name of the policy affected

  • Policy JSON: Policy content in JSON format

  • Audit User: User who performed the change

  • Action: Type of action

  • Source: Origin system of the change

  • Description: Description of the policy update

Bucket/Folder Permissions-Level Audit

  • Date: Date and time of the permission-related change

  • Data Source: Connector or data source impacted

  • Buckets/Folders: Name of the bucket or folder

  • Type: Indicates whether the object is a bucket or folder

  • Roles/Users: Entities with assigned permissions

  • Permissions: List of permissions modified

  • Audit User: User who executed the change

  • Source: Origin system of the change

  • Action: Nature of the permission change

  • Description: Summary of what was modified in the permissions


Copyright © 2025, OvalEdge LLC, Peachtree Corners GA USA

Last updated

Was this helpful?