Note: When you configure WebSEAL (or any other Access Manager component) you are being asked if you want to use Tivoli common logging . If you decide to opt for this common logging feature your WebSEAL log files will be located at C:\Program Files\IBM\tivoli\common\DPW\logs\www-default\log. Stanza entries for configuring traditional HTTP logging are located in the [logging] stanza of the WebSEAL configuration file. By default, HTTP logging is enabled in the WebSEAL configuration file and configuration looks like: [logging] requests = yes referers = yes agents = yes Along with these options, there are a couple more that can be defined in the [logging] stanza: gmt-time The value can be yes or no . Yes specifies that timestamps in each HTTP log file be recorded in Greenwich Mean Time (GMT) instead of the local time zone. By default, the local time zone is used (value is set to no ). Specifies the maximum size to which each of the HTTP log files can grow. Default value in bytes is 2000000. Depends on the value; behavior is similar to the rollover_size parameter in the log file agent. Specifies the frequency with which the server forces a flush of the log file buffers. Depends on the value; behavior is similar to the flush_interval parameter in the log file agent. max-size flush-time When using virtual hosts, you can use the following configuration parameters in the [logging] stanza to distinguish between requests that are to different virtual hosts: [logging] host-header-in-request-log = {yes | no} absolute-uri-in-request-log = {yes | no} When you enable the host-header-in-request-log entry in the configuration file, the log contains the header at the front of each line in the request log and in the combined log. When you enable the absolute-uri-in-request-log entry in the configuration file, the log contains the absolute URI. This information is included in the request log, the combined log, and HTTP audit records. Chapter 6. Auditing and troubleshooting 207