The default audit module logs authentication and authorization requests to the server log file. For information on changing the location of the log file, see To Configure General Logging Settings.
Authentication log entries include the following information:
Names of users who attempted to authenticate
The realm that processed the access request
The requested Web module URI or EJB component
Success or failure of the request
Regardless of whether audit logging is enabled, the Enterprise Server logs all denied authentication events.
Authorization log entries include the following information:
Names of authenticated users, if any
The requested Web URI or EJB component
Success or failure of the requests
The Security page opens.