EDGEBIC How-To

How to Review the Security Audit Trail in EDGEBIC

User Solutions TeamUser Solutions Team
|
6 min read

EDGEBIC by User Solutions records every security event, sign-ins, failed sign-ins, lockouts, user and role changes, in an append-only trail inside the database. There is currently no viewing screen for that trail in the application. It exists as a durable record your administrator or support can query when a compliance or investigation question genuinely needs it. Here is how to get at it, and which screens answer the neighboring questions you can handle yourself.

Every task in this library is mapped on the EDGEBIC how-to hub. For the access model the trail is recording, start with how to create a role.

Before You Start

  • Know whether your question is about access or about production. That single distinction routes you to completely different places, and getting it wrong costs an afternoon.
  • Know the window you care about. "Recently" is not something anyone can query, and the trail grows with every sign-in in the plant.
  • Know that the trail is append-only. Nothing has been deleted, so if an event happened it is recorded, even for accounts that were later renamed or removed.

Step 1: Route the Question First

Most questions people bring to "the audit log" are not security questions at all.

Your questionWhere it is answered
Who moved this job, and why?Reschedule History report
Which machine did this operation get swapped to?Resource Replacement Audit report
Is this account locked, or deactivated?Users screen, Settings, Security
When did this person last sign in?Users screen, Last login column
Who granted this permission, and when?Security trail, via an extract
Show an auditor every failed sign-in last quarterSecurity trail, via an extract

The first four you run yourself in seconds. Only the last two need anyone to touch the database.

Step 2: Check What Is Already On Screen

Open Settings, then Security, then Users. The grid carries the columns that answer the everyday version of most access questions.

ColumnWhat it settles
ActiveWhether somebody deactivated the account
LockedWhether the account is locked after failed attempts
Last loginWhen that account genuinely last got in
RolesWhat the person's access is actually built from

For a stuck user this is usually the whole investigation. Select them, click Unlock or Activate / Deactivate, and they are working again. No extract required.

Step 3: Use the Real Reports for Schedule Questions

If the question turned out to be about the plan rather than about access, two genuine reports cover it.

Reschedule History gives every reschedule event in a date window: old versus new start and end, days moved, who triggered it, and the reason if one was entered. This is the "who moved my job and why" report. See how to run the reschedule history report.

Resource Replacement Audit gives every work center swap with the actor and reason, which is the where companion to Reschedule History's when.

For a single job's full story, the job audit trail pulls it together. Both report grids support the standard filtering tools, covered in how to filter a report with the filter editor.

Step 4: Request a Security Trail Extract

When the question genuinely needs the security trail, raise it with your administrator or support. Make the request specific, because a vague one produces either nothing useful or an unreadable volume of rows.

Give them four things:

  1. The window. Exact dates, not "last month or so."
  2. The scope. One username, or plant-wide.
  3. The event kinds. Sign-in events, account changes, permission changes, or all three.
  4. What the answer is for. An auditor's evidence pack and a "what happened to Dave this morning" question want very different extracts.

Step 5: Read a Sequence, Not a Row

Whatever comes back, single rows rarely settle anything. Sequences do.

  • Several failed sign-ins in one minute, then a lockout. A person mistyping, or a saved password on a second machine.
  • Failed sign-ins spread across an hour, outside that person's shift. Worth escalating.
  • A password reset, then failures, then a success. Somebody was still using the old password on a device they forgot about.
  • A permission change, then activity on a new screen. The access change and its use, in order.

How to Check You Got the Right Answer

  • The window matches. Confirm the extract's first and last timestamps actually bracket the period you asked about.
  • The account states line up. Cross-check a lockout in the extract against the Locked column on Users.
  • You are not in the wrong trail. If the answer you needed was about a job rather than an account, you want Reschedule History, and no security extract will ever contain it.

Common Mistakes

  • Hunting for a viewing screen. There isn't one. The trail is queried, not browsed, and time spent looking for the menu item is time lost.
  • Asking for "the audit log" with no window. Every sign-in in the plant is in there. Scope the request.
  • Expecting production changes in it. Access only. Schedule changes live in the reports.
  • Reading one row in isolation. A single failed sign-in means almost nothing.
  • Only asking after an incident. A periodic look at the Users grid finds the account nobody deactivated when someone left, which is the thing most worth finding, and it needs no extract at all.

See how EDGEBIC controls and records access across the plant on the EDGEBIC product page.

Expert Q&A: Deep Dive

Q: A user was locked out this morning and swears they typed the right password. What can I check without an extract?

A: Start with the Users screen under Settings, Security, because it answers most of this without anyone querying a database. The Locked column tells you whether the account is actually locked, the Active column tells you whether somebody deactivated it, and Last login tells you when that account genuinely last got in. Between those three you can usually distinguish a lockout from a deactivation from a plain wrong password, and Unlock puts them back to work immediately. Ask for a trail extract only when the answer matters beyond getting the person working again, for example if the attempts arrived outside that person's shift and you want the timestamps on record.

Q: An auditor wants proof of who could delete jobs last quarter. How do I produce that?

A: Raise it with your administrator or support, because the security trail is queried rather than browsed. Ask for a specific window and specific event kinds rather than everything, since a plant that signs in every morning generates a lot of rows, and say up front whether you need the access changes, the sign-in events, or both. The trail is append-only, so nothing has been pruned and the entries stay accurate even for accounts that were later renamed or removed. If the auditor's real question turns out to be about production rather than access, the Reschedule History and Resource Replacement Audit reports cover it directly and you can run those yourself.

Frequently Asked Questions

Ready to Transform Your Production Scheduling?

User Solutions has been helping manufacturers optimize their production schedules for over 35 years. One-time license, 5-day implementation.

User Solutions Team

User Solutions Team

Manufacturing Software Experts

User Solutions has been developing production planning and scheduling software for manufacturers since 1991. Our team combines 35+ years of manufacturing software expertise with deep industry knowledge to help factories optimize their operations.

Let's Solve Your Challenges Together