The following table lists the information contained in audit events related to the Logger platform. All events include the following fields.
duser—UserNameduid—User IDsrc—IP address of clientdst—IP address of appliancecat—Device Event Categorycn1—Session numbercn1label—SessionAdditional fields (if applicable) are listed in the following table.
|
Device Event Class ID |
Sev. |
Device Event Category (cat) |
Message |
Additional Fields |
|---|---|---|---|---|
|
platform:200 |
5 |
/Platform/Authentication/ |
Failed password change |
|
|
platform:201 |
7 |
/Platform/Authentication/Failure |
Failed login attempt |
|
|
platform:202 |
5 |
/Platform/Authentication/ |
Password changed |
cs1: Affected User Id |
|
platform:203 |
7 |
/Platform/Authentication/ |
Login attempt by inactive user |
|
|
platform:205 |
7 |
/Platform/Authentication/PasswordChange/AdminFailure |
Automated password reset attempt made for admin account |
duser: admin |
|
platform:207 |
7 |
/Platform/Authentication/PasswordChange/UnknownUser |
Automated password reset attempted for non-existent user |
duser: username cs1: username |
|
platform:213 |
7 |
/Platform/Configuration |
Audit forwarding modified |
cs1: Audit Forwarders |
|
platform:220 |
5 |
/Platform/Certificate |
Installed certificate |
cs1: Network Protocol |
|
platform:221 |
7 |
/Platform/Certificate/Mismatch |
Certificate mismatch failure |
cs1: Network Protocol |
|
platform:222 |
1 |
/Platform/Certificate/Request |
Created certificate signing request |
cs1: Certificate Signing Request |
|
platform:224 |
5 |
/Platform/Certificate/ |
Re-generate self-signed certificate |
cs1: Certificate Signing Request |
|
platform:226 |
7 |
/Platform/Update/Failure/ |
Uploaded update file damaged or corrupt |
cs1: Error |
|
platform:227 |
5 |
/Platform/Update/Applied |
Update installation success |
cs1: Update Name |
|
platform:228 |
7 |
/Platform/Update/Failure |
Update installation failure |
cs1: Error |
|
platform:230 |
3 |
/Platform/Authentication |
Successful login |
|
|
platform:234 |
7 |
/Platform/Authentication |
Failed login attempt (LOCKED) |
|
|
platform:239 |
3 |
/Platform/Authentication |
User logout |
|
|
platform:240 |
3 |
/Platform/Authorization |
Added user group |
cn2: Current Number of Users |
|
platform:241 |
3 |
/Platform/Authorization |
Updated user group |
cn2: Current Number of Users |
|
platform:242 |
5 |
/Platform/Authorization |
Removed all members from group |
|
|
platform:243 |
3 |
/Platform/Authorization |
Modified user group membership |
|
|
platform:244 |
3 |
/Platform/Authorization |
Deleted user group |
cs1: Affected Group Name |
|
platform:245 |
3 |
/Platform/Authorization |
Added user |
cs1: Affected User Id |
|
platform:246 |
3 |
/Platform/Authorization |
Updated user |
cs1: Affected User Id |
|
platform:247 |
3 |
/Platform/Authorization/Users |
Deleted user |
cs1: Affected User Id |
|
platform:248 |
3 |
/Platform/Authentication |
Session expired |
|
|
platform:249 |
7 |
/Platform/Authentication |
Account locked |
|
|
platform:250 |
5 |
/Platform/Storage/RFS |
Added remote mount point |
cs1: RFS Mount Name |
|
platform:251 |
5 |
/Platform/Storage/RFS |
Edited remote mount point |
cs1: RFS Mount Name |
|
platform:252 |
7 |
/Platform/Storage/RFS |
Failed to create remote mount point |
cs1: Server |
|
platform:253 |
5 |
/Platform/Storage/RFS |
Removed remote mount point |
cs1: RFS Mount Name |
|
platform:254 |
5 |
/Platform/Storage/SAN |
Destroyed SAN Logical Unit |
cs1: Volume label |
|
platform:255 |
5 |
/Platform/Storage/SAN |
Attached SAN Logical Unit |
cn2: Volume size (in MB) |
|
platform:256 |
7 |
/Platform/Storage/SAN |
Detached SAN Logical Unit |
cs1: Storage unit details |
|
platform:259 |
5 |
/Platform/Storage/SAN |
Reattached SAN Logical Unit |
cs1: Volume label |
|
platform:260 |
5 |
/Platform/Configuration |
Static route modified |
cs1: Destination |
|
platform:261 |
5 |
/Platform/Configuration |
Static route removed |
cs1: Destination |
|
platform:262 |
5 |
/Platform/Configuration |
Appliance time modified |
cs1: Old Date/Time |
|
platform:263 |
5 |
/Platform/Configuration |
NIC settings modified |
cs1: NIC |
|
platform:264 |
5 |
/Platform/Configuration |
NTP server settings modified |
cs1: NTP Servers |
|
platform:265 |
5 |
/Platform/Configuration |
DNS settings modified |
|
|
platform:266 |
5 |
/Platform/Configuration |
Hosts file modified |
cs1: Difference from previous hosts file |
|
platform:267 |
5 |
/Platform/Configuration |
SMTP settings modified |
cs1: EMail Address |
|
platform:268 |
5 |
/Platform/Configuration |
Static route added |
cs1: Destination |
|
platform:270 |
5 |
/Platform/Authorization |
Inactive user disabled |
cs1: User Login |
|
platform:280 |
7 |
/Appliance/State/Reboot |
Appliance reboot initiated |
|
|
platform:281 |
3 |
/Appliance/State/Reboot |
Appliance reboot canceled |
|
|
platform:282 |
7 |
/Appliance/State/ |
Appliance poweroff initiated |
|
|
platform:284 |
5 |
/Platform/Storage/ |
Enabled SAN Multipathing |
cs1: Multipath Configuration |
|
platform:285 |
5 |
/Platform/Storage/ |
Disabled SAN Multipathing |
|
|
platform:300 |
5 |
/Platform/Certificate |
Installed trusted certificate |
cs1: Certificate details |
|
platform:301 |
5 |
/Platform/Certificate |
Installed certificate revocation list |
cs1: CRL details |
|
platform:302 |
5 |
/Platform/Certificate/Delete |
Deleted trusted certificate |
cs1: Certificate details |
|
platform:303 |
5 |
/Platform/Certificate/ |
Deleted certificate revocation list |
cs1: CRL details |
|
platform:304 |
7 |
/Platform/Certificate/ |
Failed installing trusted certificate |
cs1: Error |
|
platform:305 |
7 |
/Platform/Certificate/ |
Failed installing certificate revocation list |
cs1: Error |
|
platform:306 |
5 |
/Platform/Process/Start |
Start process |
cs1: Process Name |
|
platform:307 |
5 |
/Platform/Process/Stop |
Stop process |
cs1: Process Name |
|
platform:308 |
5 |
/Platform/Process/Restart |
Restart process |
cs1: Process Name |
|
platform:310 |
5 |
/Platform/Configuration |
Enabled FIPS mode |
|
|
platform:311 |
7 |
/Platform/Configuration |
Disabled FIPS mode |
|
|
platform:312 |
7 |
/Platform/Configuration |
Web server cipher strength changed |
cs1: New Value |
|
platform:320 |
3 |
/Appliance/State |
Appliance poweroff canceled |
|
|
platform:371 |
5 |
/Platform/Service/Restart |
Restarted OS service |
cs1: Service Name |
|
platform:400 |
2 |
/Platform/Diagnostics |
Ran diagnostic command |
cs1: Diagnostic Command |
|
platform:407 |
7 |
/Platform/Certificate |
SSL certificate expiration warning |
cs1: Issuer |
|
platform:408 |
5 |
/Appliance/State/Startup |
Appliance startup completed |
deviceCustomDate1: Startup Date |
|
platform:409 |
3 |
/Platform/Configuration |
Configure login warning banner |
cs1: Acknowledgment Prompt |
|
platform:410 |
5 |
/Platform/Configuration |
Network settings modified |
cs1: Gateway |
|
platform:411 |
5 |
/Platform/Authentication |
Automated Password Reset |
cn2: User ID |
|
platform:412 |
3 |
/Platform/Configuration |
Set Locale |
cs1: Locale |
|
platform:440 |
3 |
/Platform/Configuration/ |
SNMP configuration modified |
cn2: Port Number |
|
platform:460 |
3 |
/Platform/Network/Alias/Add |
NIC alias added |
cs1: NIC |
|
platform:462 |
3 |
/Platform/Network/Alias /Remove |
NIC alias removed |
cs1: NIC |
|
platform:500 |
5 |
/Platform/Authorization |
Remove member from group |
cs1: Affected Group Name |
|
platform:501 |
5 |
/Platform/Authorization |
Group member added |
cs1: Affected Group Name |
|
platform:502 |
5 |
/Platform/Authorization |
User removed from group |
cs1: Affected Group Name |
|
platform:503 |
5 |
/Platform/Authorization |
User added to group |
cs1: Affected Group Name |
|
platform:530 |
5 |
/Platform/Configuration |
Authentication Session settings successfully changed. |
cn2: New Value |
|
platform:540 |
5 |
/Platform/Configuration |
Password Lockout settings successfully updated. |
cn2: New Value |
|
platform:550 |
5 |
/Platform/Configuration |
Password Expiration settings successfully updated. |
cn2: New Value |
|
platform:560 |
5 |
/Platform/Configuration |
Password Validation settings successfully updated. |
cn2: New Value |
|
platform:570 |
5 |
/Platform/Configuration |
Password Automated Password Reset setting successfully updated. |
cs1: Parameter Changed |
|
platform:580 |
5 |
/Platform/Configuration |
Client Certificate authentication settings successfully changed. |
cs1: Parameter Changed |
|
platform:590 |
5 |
/Platform/Configuration |
RADIUS authentication settings successfully changed. |
cs1: Parameter Changed |
|
platform:600 |
5 |
/Platform/Configuration |
LDAP authentication settings successfully changed. |
cs1: Parameter Changed |
|
platform:610 |
5 |
/Platform/Configuration |
Global Authentication settings successfully changed. |
cs1: Parameter Changed |