System administrators can view a history of policy match events along with the policy (the set of rules) that were in effect at the time of the event. This allows administrators to view and troubleshoot policy matches.
To view the policy associated with a match rule event, click on the desired event within the Events page. The Event Details window is displayed on the right of the page. Click the View evaluation link associated with the matching rule.
NOTE! If you select a continuous authentication-related event, it will not show the view evaluation option. You must select the "POLICY - ALLOW" or "POLICY - DENY" event. Using a filter to get easier to read list is recommended.
The policy rules that were in effect for the selected match event rule are displayed.
Please sign in to leave a comment.