Is there an OOTB way to audit API access?

rogerburns
Tera Expert

Hello -

We have several API accounts using REST calls within our instances.  Our security team asked us to audit what is being done by the API accounts.  They have the ITIL role, which gives them base access to all ITSM tables, and some other tables due to roles embedded into ITIL.  Is there an OOTB way or simple way to identify what tables, and what transactions the API accounts are doing in those tables?  We do not provide them roles to scoped applications with privileged data, but are still interested in what might be happening and how to monitor it, as needed.  Thanks for any suggestions. 

1 ACCEPTED SOLUTION

Tony Chatfield1
Kilo Patron

In the menu there is a module 'REST & SOAP API Analytics'
This would be a good starting point, with Usage by Requester providing account specific details of tables accessed.

View solution in original post

1 REPLY 1

Tony Chatfield1
Kilo Patron

In the menu there is a module 'REST & SOAP API Analytics'
This would be a good starting point, with Usage by Requester providing account specific details of tables accessed.