SHARP

Language

Security Settings

When settings are changed, the changes will take effect after the machine is restarted. For details on restarting this machine, see " TURNING ON THE POWER".

Password Setting

Password Policy Settings

This setting is used when you want to set a more strict password or when users who have not logged in for a specified period of time are to be deleted.

Password Policy Settings

Enables this option when you want to make your existing password settings more strict.

Factory default settings:
Disable
If this setting is set to [Disable], there is a risk that a password that is susceptible to brute force attacks may be set when entering a password for user authentication.

Admin Password

Changes the setting of the administrator password.

Minimum Password Length

Specifies the number of characters for the password to be entered.

Factory default settings:
5

Enable Password Creation Rules

When setting a password, make sure that it contains at least one or more numbers, uppercase and lowercase letters of the alphabet, and symbols.
The characters that can be entered are as follows.

  • Numbers: 0 to 9
  • Upper case alphabet: A to Z
  • Lower case alphabet: a to z
  • Symbols: ! @ # $ % ^ & * ( ) “ ‘ + , - . / : ; < = > ? [ \ ] _ ` { | } ~ and spaces
If you enable this setting, you will need to enter at least four characters: one each for numbers, uppercase alphabet, lowercase alphabet, and symbols. Even if you set "Minimum Password Length" to 3 or less, you will still need to enter 4 characters.
Factory default settings:
Disable

Prohibit Reuse of Current Password

Check if the password you set before the change is the same as the password after the change, and if it is the same, you will not be able to register it. (However, if "Minimum Password Length" is 0, this setting cannot be used.)

Factory default settings:
Disable

User Password

Changes the setting of the user password.

Minimum Password Length

Specifies the number of characters for the password to be entered.

Factory default settings:
5

Enable Password Creation Rules

When setting a password, make sure that it contains at least one or more numbers, uppercase and lowercase letters of the alphabet, and symbols.
The characters that can be entered are as follows.

  • Numbers: 0 to 9
  • Upper case alphabet: A to Z
  • Lower case alphabet: a to z
  • Symbols: ! @ # $ % ^ & * ( ) “ ‘ + , - . / : ; < = > ? [ \ ] _ ` { | } ~ and spaces
If you enable this setting, you will need to enter at least four characters: one each for numbers, uppercase alphabet, lowercase alphabet, and symbols. Even if you set "Minimum Password Length" to 3 or less, you will still need to enter 4 characters.
Factory default settings:
Disable

Prohibit Reuse of Current Password

Check if the password you set before the change is the same as the password after the change, and if it is the same, you will not be able to register it. (However, if "Minimum Password Length" is 0, this setting cannot be used.)

Factory default settings:
Disable

Delete Users who Have not Logged in for a Specified Period of Time

Deletes users who have not logged in to the machine for the specified period from the machine’s user list.

Counting the days

  • If the user logs in before this setting is enabled, the number of days will be counted from the day after the setting is registered.
  • If the user logs in after this setting is enabled, the number of days will be counted from the day after the last login.
  • If a new user is registered after this setting is enabled, the number of days will be counted from the day after the user's registration date.
  • Users imported via st orage backup will be counted from the day after import.
Factory default settings:
Disable

Delete timing

  • Users will be deleted at the time the date changes (0:00) after the specified period has passed.
  • If the machine is in energy saving mode or turned off, the user will be deleted when the machine is restored or turned on.
  • If the number of days for this setting is shortened, the corresponding user will be deleted after the setting is registered.
Factory default settings:
Disable, Period:365
  • Users who are set as fixed users are excluded from this setting.
  • If you enable this setting and then change the setting to disable it, the days count will be reset.

Prohibit Reuse of Deleted User's Account Name

Prohibits the reregistration of user accounts (login names) once they have been deleted. This setting can be used to prohibit reregistration for a certain period of time or for no period of time.
After enabling the setting, set the period of time to prohibit reregistration. If you select "Undefined", you can prohibit reregistration without setting a period.
If [Case sensitivity of login name is enabled.] is enabled in the authentication settings, it will be judged case sensitive. If it is disabled, it will be judged without distinguishing case.
Example: Deleted login name: ABC, login name to be registered: Abc
If [Case sensitivity of login name is enabled.] is enabled in the authentication settings, the login name Abc can be registered because bc is in lower case. If it is disabled, Abc cannot be registered.

Factory default settings:
Disable, Period:365
  • The login names of user accounts that have been deleted since the time this setting was enabled are recorded in the list, up to a maximum of 2000. When the number of user accounts exceeds 2000, the login names of the oldest user accounts will be deleted.
  • When this setting is enabled and then disabled, the login name record of the deleted user account will be erased.
  • The login names of user accounts that are deleted when this setting is disabled will not be recorded.
  • The day of deletion is the first day, and the login names of user accounts that have exceeded the set period will be removed from the list.
  • The login names of user accounts deleted by [Delete All Users] in the user list will not be recorded in the list and will not be subject to this setting.

Password Change

Restrict Device Web Page Access Via Password

Use this setting to display the login screen and require login in order to access the Web server.

Change Password

The administrator password can be changed.
When you change the password, be sure to remember the new password.

  • Enter a password consisting of 5 to 255 characters, and tap the [Store] key. Your setting is made valid only when the machine is turned On again.
  • The user-level authentication password is required to add, edit or delete the destination. When you log on, enter "users" as the user name. Then, enter the user password that you have registered with this option.
    The administrator-level authentication password is required to select all settings and the same functions as those available with the user-level password. When you log on, enter "admin" as the user name. Then, enter the administrator password that you have registered with this option.
  • If you tap the [Store] key without entering a password, the previously set value is assumed. Password protection is enabled by default.

In the factory default state, the user password must be entered. (For the default administrator password, see Start Guide.)
For Europe, see Start Guide.

Condition Settings

Restrict Print Jobs

You can set up settings for document filing, My Folder Prints, and other print-related settings. You can cancel printer jobs other than hold prints or force all printer jobs to be held.

Factory default settings:
Disable

Function to Use

Select the function that uses this setting.

Factory default settings:
Document Filing

Restrict Operation

This is set when Document Filing is selected in "Function to Use".

Item Description

Force Retention

This setting forcibly sets all print jobs as print hold jobs, even jobs for which print hold is not selected.

Disable Job

Prohibit all print jobs other than print hold jobs.

Factory default settings:
Force Retention

If this setting is disabled, print data that may contain personal information/privacy information can be printed without the user being present.

Automatic Deletion of Suspended Print Jobs

If the job is interrupted due to a paper jam, etc., the job is automatically deleted after the time set in "Time until automatic deletion" has elapsed.

Factory default settings:
Disable

Time until Suspended Print Jobs are Automatically Deleted

Set the time after stopping a job to automatically deleting the job.

Factory default settings:
5 minutes

Reject Requests from External Sites

You can reject the request from external sites.

Factory default settings:
Enabled

If Firmware Corruption is Detected, Restore It

When the machine starts up, the firmware is inspected, and if any damage is found, it automatically recovers to the state before the damage.

Factory default settings:
Disable

Apply Security Policy

The default administrator is displayed at login. Set whether to apply the security policy on this machine.

Factory default settings:
Disable

Mandatory Access Control

Set whether to perform forced access control. Once set, access to all files inside the machine will be forcibly controlled.

Factory default settings:
Disable
If this setting is set to [Disable], there is a risk that a malicious program that leaks data that may include personal information/privacy information through system intrusion may be able to operate.

Job Status Jobs Completed List Display Setting

Set to show/hide the completion screen of the job status screen.

Factory default settings:
All disable

Job Status Display Setting

Sets the contents to be displayed in the job status. For printing, you can choose to show or hide the file name. For image send, the destination can be shown or hidden.

Factory default settings:
All disable

If you disable this setting, job information that may include personal information/privacy information will be viewable by third parties other than the user.

Port Control

For the various major ports used in the system, set the prohibition/permission and port number, and tap the [Store] key.
The ports that can be set are as follows.

Server Port Factory default settings Client Port Factory default settings
Port Control Enable / Disable Port Control Enable / Disable

HTTP*

80

Enabled

HTTP*

Enabled

HTTPS

443

Enabled

HTTPS

Enabled

FTP Print*

21

Enabled

FTP*

Enabled

Raw Print*

9100

Enabled

FTPS

Enabled

LPD*

515

Enabled

SMTP*

Enabled

IPP*

631

Enabled

SMTP-SSL/TLS

Enabled

IPP-SSL/TLS

443

Disabled

POP3*

Enabled

Tandem Output Receive *

50001

Enabled

POP3-SSL/TLS

Enabled

PC Scan*

52000

Enabled

SNMP-TRAP*

162

Enabled

Remote Operation Panel *

5900

Enabled

Notify Job End*

Enabled

SNMPD

161

Enabled

LDAP*

Enabled

SMB

Disable

LDAP-SSL/TLS

Enabled

SMTP*

Enabled

SMB

Enabled

WSD*

Enabled

SNTP*

Enabled

Print Release *

53000

Enabled

mDNS*

Enabled

Sharp OSA (Expansion Platform)

Tandem Output Send*

Enabled

  • HTTP*

10080

Enabled

Data Backup (Send)*

Enabled

  • HTTPS

1443

Enabled

Print Release*

Enabled

IPP INFRA

Enabled

syslog*

514

Enabled

syslog-SSL/TLS

6514

Enabled

* If these settings are set to [Enable], insecure communication will be possible, and there is a risk that data that may include personal information/private information may be intercepted.

Filter Setting

You can set the filter by an IP or MAC address to prevent an unauthorised access to the machine via a network.
Set the IP or MAC address filter and tap the [Store] key.

Factory default settings:
Disable

IP Address Filter Settings

This option sets an IP address.
You can specify whether to allow or prohibit access to the machine from the IP address you set.

Factory default settings:
Enable

MAC Address Filter Settings

This option sets a MAC address.
It allows access to the machine from the MAC address you set.

Intrusion/Attack Detection

This section explains how to protect the machine by partially blocking communications with an attempt to attack the machine via network.
If the multifunction device receives more than the set number of communications from the same IP address within the set period, communication from that IP address is prohibited.
IP addresses whose communication is prohibited are recorded in the audit log and registered as a reception refusal list.
In addition, those IP addresses are notified by e-mail to the addresses in the e-mail alert message list 1/2 and dealer e-mail alert message list.
The removal of the IP address from the rejection list is also recorded in the audit log.
The maximum number of IP addresses that can be registered in the reception rejection list is 100, and when the number reaches 100, external connection requests for multifunction devices will not be accepted.

Factory default settings:
Disable

  • Even if the power is turned on/off, the intrusion/attack detection settings and reception refusal list are retained.
  • When you execute [Reset the NIC] or [Restore Factory Defaults], the intrusion / attack detection settings and reception rejection list are initialized.
  • When you want to send e-mail to the E-mail alert address list or E-mail alert dealer address list, enable [Security Alert] in [Alerts Message].

List of Denied IP Addresses

Item Description

IP Address

Displays the IP address that is rejected. The default setting is "OFF".

Start Time of Incoming Packet Denials

Displays the date and time when reception refusal started.

Total

Displays the number registered in the reception rejection list.

Factory default settings:
Allow

Virus Scan Setting

This setting is available when the virus detection kit is installed. Specifies the settings for virus detection.

When you open the Virus Scan Setting for the first time, or when you go to the Virus Scan Setting if you have not agreed to the software license agreement when you opened it before, the software license agreement screen will appear. Check the contents, and if you have no problems using the software, select [Agree].

Virus Scan

Specifies whether to use the virus scan function.

Factory default settings:
Disable

Virus Scan Settings

Perform Virus Scan on Input-Output Data

When the input/output data of the machine is generated, the corresponding data is scanned for viruses.

Factory default settings:
Disable
If this is set to [Disable], and combined with insecure communication, there is a risk that data that may include personal information/privacy information may be intercepted.

Perform Virus Scan at Specified Time

Scans for viruses at the specified date and time.

Factory default settings:
Disable

Perform Virus Scan Now

Perform this setting when you want to scan for viruses immediately.

Time Schedule

Specifies the schedule for virus scan.

Every Day

When this setting is enabled, a daily virus scan will be performed.
(Start Time)
Sets the time to start scanning.

Factory default settings:
12:00

Every Week

When this setting is enabled, a virus scan will be performed every week on the specified day and time.
(Day of the Week)
Sets the day of the week to start scanning.

Factory default settings:
Monday
(Start Time)
Sets the time to start scanning.
Factory default settings:
12:00
When the machine is not turned on at the date and time specified in the "Time Schedule", the virus scan will start the next time the machine is started.

Every Month

When this setting is enabled, virus scan will be performed on the specified day and time.
(Date)
Sets the date when the scan will start.
For months that have days that do not exist (for example, February and April when 31 is set), run at the end of the month.

Factory default settings:
1
(Start Time)
Sets the time to start scanning.
Factory default settings:
12:00

When the machine is not turned on at the date and time specified in the "Time Schedule", the following operation is performed.
  • Even when the Audit Log is enabled, virus scan failures are not recorded.
  • When you set "Every Day", the virus scan will not be performed until the same time the next day.
  • When you set "Every Week" or "Every Month", the virus scan is performed after the first start up of the machine after the time when the virus scan was not performed. Even if there are multiple times the opportunity to perform the virus scan during a period of time when the machine is not turned on, the virus scan will only be performed once after the machine is started up.

Virus Scan Target

Select the data to be scanned for viruses.

  • System File (Firmware)
  • Embedded Application
  • NAS Stored Data
Factory default settings:
All enabled

Virus Definition File Update Setting

Perform Update Now

Perform this setting when you want to update the virus scan definition files immediately

SSL/TLS Settings

SSL/TLS can be used for data transmission over a network.
SSL/TLS is a protocol that enables the encryption of information communicated over a network. Encrypting data makes it possible to transmit and receive sensitive information safely.
Data encryption can be set by the following protocols.

Setting of SSL/TLS

Server Port

  • HTTPS: Apply SSL/TLS encryption to HTTP communication.
  • Factory default settings:
    Enable
  • IPP-SSL/TLS: Apply SSL/TLS encryption to IPP communication.
  • Factory default settings:
    Disable
  • Redirect HTTP to HTTPS in Device Web Page Access: When this setting is enabled, all communication that attempts to access the machine by HTTP is redirected to HTTPS.
  • Factory default settings:
    Disable
If this is set to [Disable], and combined with insecure communication, there is a risk that data that may include personal information/privacy information may be intercepted.

Client Port

  • HTTPS: Apply SSL/TLS encryption to HTTP communication.
  • Factory default settings:
    Enable
  • FTPS: Apply FTP encryption to HTTP communication.
  • Factory default settings:
    Enable
  • SMTP-SSL/TLS: Apply SMTP encryption to HTTP communication.
  • Factory default settings:
    Enable
If you select [Disable], unsecure SMTP communication will be possible, and there is a risk that the data transmitted may be subject to eavesdropping if it may contain personal or private information.
  • POP3-SSL/TLS: Apply SSL/TLS encryption to communication using POP3.
  • Factory default settings:
    Enable
If you select [Disable], unsecure POP3 communication will be possible, and there is a risk that data that may include personal information/private information may be intercepted.
  • LDAP-SSL/TLS: Apply SSL/TLS encryption to communication using LDAP.
  • Factory default settings:
    Enable
  • syslog-SSL/TLS: Apply SSL/TLS encryption when sending audit logs.
  • Factory default settings:
    Enable
  • Verify Signature of Server Certificate of the Other Party: Validate the certificate of the server you are communicating with.
  • Factory default settings:
    Disable
    • Even if "Verify Signature of Server Certificate of the Other Party" is enabled, when "Global Address Search" or "Find My Address" is performed when the search destination is an LDAP server, the server certificate of the destination is not validated.
    • If "Verify Signature of Server Certificate of the Other Party" is disabled, you may connect to an unintended server and data that may include personal or private information may be transmitted to that server.
  • TLS1.2: Use only TLS1.2.
  • Factory default settings:
    Enable
  • TLS1.3: Use only TLS1.3.
  • Factory default settings:
    Enable

Level of Encryption

The encryption strength can be set to one of three levels.

Factory default settings:
Low

Device Certificate

Certificate Status

Displays the status of the certificate required for SSL/TLS communication. Click the [Select] key to install the certificate.

Certificate Information

If the device certificate is installed, click the [Show] key to display the certificate information.

Select Device Certificate

Click the [Select] key to display the device certificates that have already been registered. Select from them.

S/MIME Settings

S/MIME Settings

Sets whether or not to use S/MIME for scan to E-mail.

Factory default settings:
Disable
By enabling this setting, you can protect document data that may include personal information sent by email.

Device Certificate

Certificate Status

Shows the status of the certificate required for sending using S/MIME. If you want to install the certificate, click the [Select] key.

Sign Settings

Sign E-mail

Enable "Sign E-mail" to use a signature.

Factory default settings:
Always Enable

Signature Algorithm

Set the algorithm for the signature.

Factory default settings:
SHA-1

Encryption Settings

Encrypt E-mail

Sets the use of encryption.

Factory default settings:
Always Enable

Encrypt

Select the method to be used for encryption.

Factory default settings:
AES-128

Disable sending to the addresses which cannot be encrypted.

Prohibit transmission to addresses that cannot be encrypted.

Factory default settings:
Enable

Certificate Information

If the device certificate is installed, click the [Show] key to display the certificate information.

Select Device Certificate

Click the [Select] key to display the device certificates that have already been registered. Select from them.

This setting can only be set on web pages.

IPsec Settings

IPsec can be used for data transmission/reception on a network.
When IPsec is used, data can be sent and received safely without the need to configure settings for IP packet encryption in a Web browser or other higher-level application.
When enabling this settings, take the following notes.

  • It may take some time to reflect on the machine settings, and you cannot connect to the machine during this time.
  • If the Setting mode (Web version) settings are not correctly selected, connection to the machine may not be allowed, or the settings may not allow printing, scanning, or Setting mode (Web version) display. In this case, deselect this setting and change the System Settings (on Web pages).
If you enable this setting, you can protect data communications that may include personal information/privacy information from eavesdropping.

Condition Settings

IPsec Settings

Sets whether to use IPsec for transmission.

Factory default settings:
Disable

IKEv1 Settings

Pre-Shared Key

Enter the Pre-Shared Key to be used for IKEv1.

SA Lifetime (time)

Set the SA lifetime.

Factory default settings:
28800 seconds

SA Lifetime (size)

Set the SA lifetime size.

Factory default settings:
28800 KB

IKE Lifetime

Set the IKE lifetime.

Factory default settings:
30 seconds

IPsec Rules

The registered IPsec rules are displayed.
To add a new rule, click the [Add] key.
To delete a rule, select the rule you want to delete and click the [Delete] key.

IPsec Rule Registration

Rule Name

Enter a name for the IPsec rule.

Priority

Set the priority level.

Factory default settings:
1

Select the Rule Name to be the Registration Model

If there is a previously registered rule that is similar to the rule you want to create, you can create the new rule based on the registered rule.

Device Address

Set the type of IP address to be used on the machine and the port number (for IPv6, set the port number / prefix length).

Client Address

Set the destination IP address type and port number (for IPv6, set the port number / prefix length).

Protocol

Set the protocol to be used.

Factory default settings:
TCP

Filter Mode

Configure settings for the authentication method used for IPsec.

Factory default settings:
IPsec

IPsec Encryption

Configure settings for the authentication method used for IPsec.

ESP

Select to use ESP authentication.

Factory default settings:
Enable

Allow Communication not using ESP

Specify whether or not communication that does not use ESP is allowed.

Factory default settings:
Enable

AH

Select to use AH authentication.

Factory default settings:
Disable

Allow Communication not using AH

Specify whether or not communication that does not use AH is allowed.

Factory default settings:
Disable

Document Administration Function

All of the transmitted image data (sent or received by facsimile or e-mail transfer) can be forwarded to any destination.

List name Settings

Forwarding Destination Settings (Send Data)

Forward Send Data

Set a destination to forward the send data.

Factory default settings:
Disable

E-mail/Network Folder/FTP/Desktop

Select a forwarding type of the send or received image data. When determined, select the destination from the address book.

You can enter an e-mail directly.

  • Format: Select the file format for inbound routing.

Clear Setting

Releases the destination settings.

File Format

Select the file format for inbound routing.

Forwarding Destination Settings (Received Data)

Forward Received Data

Set a destination to forward the received data.

Factory default settings:
Disable

E-mail/Network Folder/FTP/Desktop

Select a forwarding type of the send or received image data. When determined, select the destination from the address book.

You can enter an e-mail directly.

  • File Format: Select the file format for inbound routing.

Clear Setting

Releases the destination settings.

File Format

Select the file format for inbound routing.

Factory default settings:
TIFF(Multi)

Hidden Pattern Print Setting

Select Hidden Pattern Print Setting.
The hidden pattern print function is effective at preventing unauthorised copying as the specified text emerges in the background on output sheets.

Initial Status Settings

Default Settings

Item Description

Hidden Pattern Print Setting

A pattern print can be printed with this settings.

Factory default settings:
All Invalid

Print Colour

Select a print colour.

Factory default settings:
Black

Exposure

Select an exposure.

Factory default settings:
Standard

Font Size

Select a font size.

Factory default settings:
48point

Angle

Select a character angle.

Factory default settings:

Font Style

Select the standard or italic character settings.

Factory default settings:
Standard

Camouflage Pattern

Set a camouflage pattern.

Factory default settings:
Pattern 1

Print Method

Select a character display pattern.

  • Character stand out.
  • The background stands out.
Factory default settings:
Positive

Print Contents Setting

Item Description

Pre-Set Word

Allows you to select a preset character string.

The following character strings can be selected.

  • DO NOT COPY, Copy Ban, Internal Use Only, Handle With Care, CONFIDENTIAL, Copy Invalid, IMPORTANT, COPY
  • Factory default settings:
    Enable, Copier

Pre-set Text

Select a stored preset character string.

This setting is ignored if [Direct Entry] is enabled.

  • DO NOT COPY, Copy Ban, Internal Use Only, Handle With Care, CONFIDENTIAL, Copy Invalid, IMPORTANT, COPY

Information Printing

Enables simultaneous printing of the following information sets.

  • Serial number, account job ID, login name/user number, number of copy control, date and time
  • Factory default settings:
    All Invalid

Disable Direct Entry

Set whether to enable direct input of print characters for tint block printing in each mode.

Factory default settings:
Disable

Contrast

Set a character contrast.
The black, magenta, and cyan can be set in any of 9 levels.

Factory default settings:
All 5

Custom Text Registration

Stores the user-created print characters. Up to 30 characters can be stored.

Tracking Information Print

Prints the tracking information at the top or bottom of output pages when copy or print job is executed.

This function forcibly prints the pre-specified traceable information to prevent an unauthorised copy.

Item Description

Tracking Information Print Setting

Set this option to print the tracking information.

Factory default settings:
Disable

Print Information

The following information can be printed.

  • Serial number, characters, account job ID, login name/user number, date and time
Factory default settings:
Serial number: Enable, Text: Disable, Account Job ID: Enable, Login Name/User Number: Enable, Date/Time: Enable

Select the Print Colour

Set the print colour.

Factory default settings:
Black

Position

Set a print position on each page.

Factory default settings:
Print Upper Side of Paper: Disable, Print Lower Side of Paper: Enable, Print Left Side of Paper: Enable, Print Right Side of Paper: Disable, Position Adjustment:1(Outer)

Font Size

Set the size of the characters to be printed.

Factory default settings:
Middle

Select the Job to Print

Set a job to print the tracking information.

Factory default settings:
All Enabled
  • If this function is specified together with another image compositing function, tracking information is printed at the top.
  • The information added at printing or the preview image of the account job ID and date/time are displayed as shown below.
  • Account job ID: 00000
    Date/time: DD/MM/YYYY hh:mm

Audit Log

Logs are created and saved for various events relating to security functions and settings.
Audit logs are created and saved in English. However, setting values such as filenames which are input from external sources are saved as-is.
Audit logs which have been saved in the internal storage can be exported by an administrator to a PC as TSV files.
You can select either the internal storage or an external server as the destination for saving audit logs.

  • When the space for saving audit logs internally becomes full, the logs are overwritten starting from the oldest ones.
  • If you enable the audit log setting, information about the user who generated the event will be recorded in the audit log.

Audit Log

"Audit Log" can be carried out as follows.
In "Settings (administrator)", select [System Settings] → [Security Settings] → [Audit Log]
Select "Security Control", "Storage/Send Settings" or "Save/Delete Audit Log".

Factory default settings:
Enable

Storage/Send Settings

"Storage/Send Settings" can be carried as follows.
In "Settings (administrator)", select [System Settings] → [Security Settings] → [Audit Log]→ [Storage/Send Settings]
Then make the storage and transmission settings.

Factory default settings:
Local Drive Store:Enable, Server Send:Disable, Enable SSL/TLS:Disable, Port Number:514, Port Number (Use SSL/TLS):6514

Save/Delete Audit Log

"Save/Delete Audit Log" can be carried out as follows.
In "Settings (administrator)", select [System Settings] → [Security Settings] → [Audit Log]→ [Save/Delete Audit Log]
Select "Save Audit Log" or "Delete Audit Log".

  • "Save Audit Log" can only be carried out from the web page.
  • If you have set a high level of security, it will not be displayed if audit logging is disabled or storage storage is disabled.

Audit Log specifications

If the audit log is saved to an external server, the audit log is temporarily saved in the buffer area reserved in the internal storage until the transmission to the external server is successful.

  • Audit logs that are successfully sent to the external server are cleared from the buffer area.
  • If the transmission to the external server fails, a warning message will be displayed on the operation panel and the screen of the web page, and the transmission will be periodically retransmitted to the external server until the transmission is successful.
The audit events and information stored in the audit log are as shown in the following table.

If the power of this machine is turned off by a method other than the procedure described in the user's manual or due to a power failure, the [End Audit] event may not be recorded. Make sure to turn off the power of this machine according to the correct procedure. We also recommend using an uninterruptible power supply (UPS) in the event of an unforeseen event such as a power outage.
Event name Date & Time
*1
Operation I/F
*2
Login Name Result
*3
Additional
Information

Audit Start

Yes

N/A

N/A

Yes

Reasons for starting

Normal start-up: main power on, panel SW pressed, reboot, timer, fax, network, waste paper tray fax paper removal, other

Other: security erase

Audit End

Yes

N/A

N/A

Yes

N/A

Job Completion

Yes

Yes

Job owner (SYSTEM)

Yes

Finished job name

I&A Success

Yes

Yes

The string entered as your login name

N/A

IP address of the login source

127.0.0.1 for the operation panel

I&A Failure

Yes

Yes

The string entered as the login name

N/A

IP address of the login source

127.0.0.1 for the operation panel

Add User

Yes

Yes

User who added

Yes

Added login name

Login Terminated

Yes

Yes

The string entered as your login name

N/A

Active termination/ Timeout

Change Password

Yes

Yes

The user who made the change

Yes

Login name of the user whose password has been changed

Change Login Name

Yes

Yes

The user who made the change

Yes

Login name after change

Delete user

Yes

Yes

User who deleted

Yes

Deleted login name (ALL if all users are deleted)

Add Auth Group

Yes

Yes

User who added

Yes

Added authority group name

Change Role

Yes

Yes

The user who made the change

Yes

  • Login name of the user whose authority group has been changed
  • Changed authority group name

Change Auth Group Setting

Yes

Yes

The user who made the change

Yes

Privilege changed settings Group Name

Add Page Limit Group

Yes

Yes

Users with additional functions

Yes

Name of the additional page limit group

Delete Page Limit Group

Yes

Yes

Users whose functions are deleted

Yes

Name of the deleted page limit group

Change Page Limit Group
Setting

Yes

Yes

Users who have changed the settings

Yes

Name of the changed page limit group

Change Time Setting

Yes

Yes

The user who made the change

Yes

N/A

Change Setting

Yes

Yes

User who made the change (“ByPolicy” when applying AD policy)

Yes

  • Setting items whose setting values have been changed
  • Set value after change

Firm Recovery

Yes

N/A

N/A

Yes

  • Firmware name
  • Firmware version after recovery

Exec Rejection

Yes

N/A

N/A

Yes

Distinguished name of firmware or embedded OSA app

TLS, IPsec communication
failure (Comm Failure)
* Communication partner is
other than the audit server

Yes

N/A

Users who are communicating

N/A

  • IP address of the communication starter
  • IP address of the communication partner
  • Communication direction
  • Reason for failure

Modify AddrBook

Yes

Yes

User who updated

Yes

  • At the time of addition: Internal management ID and destination name of the added entry
  • When deleting / changing: Internal management ID of deleted / changed entry

Firm Update

Yes

Yes

User who updated

Yes

  • Firmware name
  • Firmware version before update
  • Firmware version after update

Intrusion/Attack Detected

Yes

N/A

N/A

Yes

  • IP addresses that have been blocked
  • When the maximum number of detections is reached, "reaches limit" is added.

Release Denied Addr

Yes

Yes

Users who have been released

Yes

Released IP address

Invoke EAM App

Yes

N/A

N/A

Yes

Starting Sharp OSA External Accounts Application Additional Information: IP Address and Application Name of Sharp OSA External Account Server

CSRF Trial

Yes

Net

N/A

N/A

Attacking IP address

Enabling Embedded OSA
Applications

Yes

Yes (N/A for firmware updates)

Users who have activated the function

(default administrator for installation and update via Application Portal, system for firmware update)

for installation and update from Application Portal, "system" for firmware update)

Yes

  • Application name
  • Connection details (IP address where the activation operation was performed) (127.0.0.1 for the operation panel))

Send External Dest

Yes

Yes

Users who sent

Yes

Destination e-mail address/IP address/SMB folder path

Web Push Print

Yes

Yes

Users of the function

Yes

IP address from which the file was downloaded

Change Service Setting

Yes

Yes

Users who have changed the settings

Yes

Changed settings and their values

Switch to service mode

Yes

Yes

Service

Yes

N/A

Running in service mode

Yes

Yes

Service

Yes

Changed setting values

Sharp OSA external account
user authentication

Yes

Yes

The string entered as your login name

Yes

N/A

Scheduled Virus Scan

Yes

N/A

N/A

Success/ Failure

In case of failure, the reason

  • Interruption of running scan due to power off Interruption of the scan
  • Any other reason Interruption of a running scan due to other than the above
  • Scan failure due to errors other than the above

On-demand Virus Scan

Yes

Ope/Web

Users who requested the scan to be performed

Success/ Failure

In case of failure, the reason

  • Interruption of running scan due to power off Interruption of the scan
  • Any other reason Interruption of a running scan due to other than the above
  • Scan failure due to errors other than the above

Virus Detection

Yes

N/A

N/A

Always "Success"

One of the following

  • Firmware
  • Inbound data
  • Outbound data
  • Stored data
  • OSA app

Data identification name (file name, etc., if obtainable. N/A if not possible)

Identification name of the virus

Auto Pattern Update

Yes

N/A

N/A

Success/ Failure

In case of failure, the reason

  • Connection error to the server
  • Failed to download the pattern file
  • Incorrect system setting time
  • Scan failure due to errors other than the above

On-demand Pattern Update

Yes

Ope/Web

Users who requested the implementation of the update

Success/ Failure

In case of failure, the reason

  • Connection error to the server
  • Failed to download the pattern file
  • Incorrect system setting time
  • Scan failure due to errors other than the above

Change Setting

Yes

Yes

Users who have changed the setting values

Success/ Failure

Setting items and values for Web page (Virus Scan Setting)

*1 The date and time when the event occurred is displayed in the extended format of ISO 8601.

*2 Either Ope/Web/sNet is displayed as the operation interface. However, if it is "N / A" in the table, it will be written as "N / A".

*3 Either Success / Failure will be displayed as the result of the event.

Certificate Management

Device Certificate Management

Import

Import the certificate/private key.

This setting can only be set on web pages.

Export

Export the certificate/private key.

This setting can only be set on web pages.

Certificate Information

Shows the status of the certificate.

Creation of Certificate and Private Key

This setting can only be set on web pages.
Common Name (Required)

Enter the name to be used.

Organization

Enter the name of the organization.

Organizational Unit

Enter the name of the unit within the organization.

City/Locality

Enter the city or locality.

State/Province

Enter the state or province.

Country/Region (Required)

Enter the country code.

Sender Address

Enter the sender's E-mail address.

Certificate Start Date

Enter the start date and time for the certificate.

Certificate Validity Period

Enter the expiration date of the certificate.

Certificate Information

Enter the Certificate Information.

Certificate Signing Request (CSR) Management

Install

Install the certificate.

Certificate Information

Shows the status of the certificate.

Make of Certificate Signing Request(CSR)

Common Name (Required)

Enter the name to be used.

Organization

Enter the name of the organization.

Organizational Unit

Enter the name of the unit within the organization.

City/Locality

Enter the city or locality.

State/Province

Enter the state or province.

Subject Alternative Name

Enter the Subject Alternative Name (SAN).

Country/Region (Required)

Enter the country code.

Sender Address

Enter the sender's E-mail address.

Certificate Start Date

Enter the start date and time for the certificate.

Certificate Validity Period

Enter the expiration date of the certificate.

Certificate Information

Enter the Certificate Information.

CA Certificate Management

Import

Import the certificate.

Certificate Information

Shows the status of the certificate.

Language

Version 01a / bp71c65_usr_01a_en

↑Top of page