AEMaaCS and Audit Log
Hello AEM community,
We are looking for compliance and monitoring in our security team with our AEMaaCS solution.
I have some questions about the Audit Log and best practices on externalising it as "surprisingly for us" this is JCR nodes instead of a log file.
- I have found the Audit Log just logs Assets, Replication, Pages events... however it lacks users permissions or ACLs changes or basically any User Management events. Where this information is Audit? I know there are some logs which may contain this information. If anyone has a listing on which specific logs to enable in INFO or DEBUG mode are recommended for auditing will be great.
- Anyone can share any experience on externalising the Audit Log? Best practices on how to take this out to an external system.
- Maintenance Tasks. I have seen that Adobe is changing the strategy of 7 years of keeping Audit Log to 7 days and purging. I suppose is because performance issues in the JCR due to the amount of content that can be generated. Can anyone share if keeping 3 years of data can make the system unstable? Any recommendation?
I have read multiple articles online already, this means I am looking for personal experiences.
Regards.