Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make username of person/account logging in (unsuccessful attempt) (currently in core.log) in audit.log (TSA Security Act UK) #20293

Open
floreseo2 opened this issue Apr 17, 2024 · 0 comments
Labels
area/audit-log backlog kind/requirement New feature or idea on top of harbor

Comments

@floreseo2
Copy link

Hi there and hoping you're well -
For the Telecommunications Security Act (a new set of UK lawful regulations)- we need to please to have the following event within
the audit log of Harbor:
Make username of person/account logging in (unsuccessful attempt of login), time/date stamp (currently in core.log, but it's our understanding that core.log content doesn't work with the syslog forwarding function in Harbor, instead the event needs to be in audit.log - so thereby the issue is make unsuccessful login events with username of user, time/date stamp, available to audit.log. (Medium Priority - as the local log does have it - but can't be forwarded to SIEM/SOC).
https://assets.publishing.service.gov.uk/media/6384d09ed3bf7f7eba1f286c/E02781980_Telecommunications_Security_CoP_Accessible.pdf
(Section 5.7, page 43).
Thank you

@wy65701436 wy65701436 added kind/requirement New feature or idea on top of harbor backlog area/audit-log labels Apr 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/audit-log backlog kind/requirement New feature or idea on top of harbor
Projects
None yet
Development

No branches or pull requests

2 participants