Event Driven Audit Logging Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current audit logging systems face challenges in tracking user actions across multiple users and administrators, particularly in large enterprises, as they often fail to record detailed changes to documents or transactions, leading to unmanageable log volumes and loss of previous change details.

Innovation Solution

Implementing an event-driven audit logging system with an application-independent framework that allows for customizable logging and reporting of specific events, enabling users to select which actions to log and providing access to an event log for easy viewing and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If record level tracking is used to log all changes, then complete audit information is captured, but the volume of logs becomes overwhelming and unmanageable

Engineering Contradiction:
Improveaudit information completenessVSAvoidlog volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent segments audit logging by event types, allowing the system to divide comprehensive logging into specific, manageable event categories. This enables selective logging of only relevant events rather than all possible changes, reducing overall log volume while maintaining audit completeness for critical events.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling different logging configurations for different event types within the same system. Administrators can specify which event types to log based on their importance, creating varying levels of logging detail across different parts of the system rather than uniform logging of all events.

Inventive Principle:
Principle #3Local quality

2Loss of information

If all changes are logged at record level, then detailed audit trail is maintained, but the complexity of viewing and searching logs increases significantly

Engineering Contradiction:
Improvechange detailsVSAvoidlog management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

By segmenting logs into distinct event type categories, the patent simplifies the viewing and searching process. Users can filter logs by specific event types relevant to their needs, avoiding the complexity of searching through all possible changes. This segmentation makes log management more organized and easier to navigate.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables administrators to configure logging at the event type level, allowing them to focus on specific areas of interest. This local quality approach reduces the complexity of log management by enabling targeted viewing and searching of only the event types that are relevant to particular audit requirements.

Inventive Principle:
Principle #3Local quality

3Quantity of substance

If only the last change is recorded, then storage space is conserved, but previous change details are overwritten and lost

Engineering Contradiction:
Improvestorage spaceVSAvoidprevious change details
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent segments the audit log into multiple event type-specific logs rather than a single comprehensive log. This allows the system to retain historical data for each event type separately, preventing overwriting of previous changes while managing storage more efficiently through targeted retention policies for different event categories.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8204861B2Event driven audit logging
Publication Date: 2012.06.19 ORACLE INT CORP
  • US8204861B2 patent drawing
  • US8204861B2 patent drawing
  • US8204861B2 patent drawing

AI summary

This disclosure describes, generally, methods and systems for implementing event driven audit logging. The method includes establishing, at an audit logging system, audit logging framework configured to provide application independent connectivity and further configured to provide event driven audit logging. The method further includes receiving, at the audit logging system, a selection of an application to provide event driven auditing, enabling event driven auditing for the selected application, and receiving a selection of event types to enable for auditing by the audit logging framework. Furthermore, the method includes based on the selected event types, tracking the application actions associated with the selected events, creating an event log for the application, and providing access to the event log.