Secret Server logs events to Security Information and Event Management (SIEM) platforms that support CEF or syslog formats. These events can be correlated on the SIEM side so administrators can be alerted if specific events occur on the systems. An administrator might setup a filter for events such as;
Unlimited Administration being turned on, user lockout, heartbeat failure or Secret expiration. These events are logged with different alert levels depending on their severity.
SIEM and Log Management tools known to work with Secret Server include: ArcSight, Splunk, LogLogic and more. (Most SIEM and Log Management tools support Syslog format - meaning that they are compatible with Secret Server). Thycotic Software is an ArcSight CEF certified partner.