SNC Access Control Plugin has been activated. Info Sec Team would like to be able to search the log files to identify any Service Now users that have accessed our system and what actions have been taken. Which log file would be best suited to access?

marceiseman
Kilo Contributor

We have recently activated the SNC Access Control Plugin. Our Info Sec Team would like to be able to search the log file best suited to identify the support personnel that have accessed the system and what action were taken when they did,

Any suggestions as to the correct log file to access?

Thx in advance for your help.

1 ACCEPTED SOLUTION

Jeff Boltz1
Mega Guru

Events and Transactions:

(just some ideas)

https://[instance].service-now.com/sysevent_list.do?sysparm_query=sys_created_onONToday%40javascript%3Ags.daysAgoStart(0)%40javascript%3Ags.daysAgoEnd(0)%5EnameSTARTSWITHlogin%5Eparm1LIKEsnc&sysparm_view=

https://[instance].service-now.com/syslog_transaction_list.do?sysparm_query=urlSTARTSWITH%2F%5Esql_count%3E0%5Eresponse_time%3E25%5Esys_created_byLIKEsnc&sysparm_view=

View solution in original post

5 REPLIES 5

Jeff Boltz1
Mega Guru

Events and Transactions:

(just some ideas)

https://[instance].service-now.com/sysevent_list.do?sysparm_query=sys_created_onONToday%40javascript%3Ags.daysAgoStart(0)%40javascript%3Ags.daysAgoEnd(0)%5EnameSTARTSWITHlogin%5Eparm1LIKEsnc&sysparm_view=

https://[instance].service-now.com/syslog_transaction_list.do?sysparm_query=urlSTARTSWITH%2F%5Esql_count%3E0%5Eresponse_time%3E25%5Esys_created_byLIKEsnc&sysparm_view=

marceiseman
Kilo Contributor

Thx very much for your reply. It helps a lot!

Petter-B
Tera Contributor

Hi, 


@marceiseman wrote:

We have recently activated the SNC Access Control Plugin. Our Info Sec Team would like to be able to search the log file best suited to identify the support personnel that have accessed the system and what action were taken when they did,

Any suggestions as to the correct log file to access?

Thx in advance for your help.


You installed this a while ago, could you please share pros and cons with this solution? Gained benefits?

The only downside is having to facilitate individual snc access entries for each support call, if you don't do this quickly then you risk support calls taking longer. It is however very easy to do. 

 

The upside is your instance is that bit more secure. You have more control over who can access you instance for support and over what time period they are allowed this access. 

***If Correct/Helpful please take time mark as Correct/Helpful. It is much appreciated.***

Regards

Paul