Viewing Google Workspace CSE Records
This section describes the logs of Google Workspace events. Whenever an action is performed on an endpoint, an event is logged. The actions can be rotate keys, create endpoint, delete endpoint, wrap, unwrap, privileged-unwrap, private key sign, private key unwrap, and private key privileged-unwrap.
To view Google Workspace CSE events:
Open the CipherTrust Manager Application.
In the left pane, click Records > Server Records.
The following details are shown:
Column | Description |
---|---|
Severity | Severity of the event. The severity can be: • INFO • WARNING • ERROR • CRITICAL • FATAL |
Event Created | Time when the event is created. |
Action | Name of the action logged. The action can be: • Wrap • Unwrap • Privileged Unwrap |
Details | Details of the event. |
By | Client user who initiated the action. |
Source | Hostname of the CipherTrust Manager. |
Client | IP address of the machine where the action is performed. |
Note
In some cases, you might see the following error:invalid authorization token - cause: untrusted authentication token: square/go-jose/jwt: validation field, token issued in the future (iat)
To resolve this issue, add the Google NTP server to the CipherTrust Manager (Admin Settings > NTPs).