Two log files are used in logging activity in the SSL/TLS module:
The OPEN report, which is written upon successful completion of the SSL/TLS handshake, includes SSL/TLS attributes. If the session is interrupted, the port closes and the session activity is logged in the CLOSE report. Entries to denote successful completion and failure reasons are written to the security log file as well.
The security log file is secured by the file attribute SECURITYADMIN, which restricts the access to a user or process that has the USERDATA privilege set. If security administrator status is enabled, a user with SECADMIN status is given USERDATA privilege; otherwise, a privileged user is given USERDATA privilege.

