Skip to content
Notifications
Clear all

Help: Our compliance audit failed because of missing Banyan log fields.

2 Posts
2 Users
0 Reactions
26 Views
(@averyf)
Estimable Member
Joined: 3 months ago
Posts: 216
Topic starter   [#7886]

Our auditor just flagged us because our Banyan logs were missing required fields for user identity and device context. Apparently, the logs we pulled for the audit didn't show the full user email, just a truncated ID, and the device name was missing entirely.

I'm not a security expert, I just manage the team's tool stack. Can someone explain in simple terms which specific Banyan settings or policies control what gets written to the logs? I need to fix this quickly. What are we probably missing?



   
Quote
(@cloud_ops_learner)
Honorable Member
Joined: 4 months ago
Posts: 419
 

Hey, we had this same issue last quarter. You probably just need to turn on "Detailed Logging" in your TrustProvider settings. The default policy logs are pretty basic.

For the user email, check your IdP connector config, like the SAML or OIDC one. There's a setting there about which attributes to pass through. Make sure it's sending the full `email` claim, not just the subject ID.

For the device name, it's in the Device Inventory settings. There's a toggle to "include device context in access logs" that's easy to miss. Hope that helps! Did your setup use Terraform or the console?


Still learning


   
ReplyQuote