Datasheet

Table Of Contents
9-7
Cisco ONS 15454 SDH Reference Manual, R7.0
October 2008
Chapter 9 Security
9.3 Audit Trail
For more information on how to enable EMS secure access, refer Cisco ONS 15454 SDH Procedure
Guide for instructions.
9.3 Audit Trail
The ONS 15454 SDH maintains an audit trail log that resides on the TCC2/TCC2P. This record shows
who has accessed the system and what operations were performed during a given time period. The log
includes authorized Cisco logins and logouts using the operating system command line interface, Cisco
Transport Controller (CTC), and TL1; the log also includes FTP actions, circuit creation/deletion, and
user/system generated actions.
Event monitoring is also recorded in the audit log. An event is defined as the change in status of an
element within the network. External events, internal events, attribute changes, and software
upload/download activities are recorded in the audit trail.
Audit trails are useful for maintaining security, recovering lost transactions and enforcing accountability.
Accountability is the ability to trace user activities by associating a process or action with a specific user.
To view the audit trail log, refer to the Cisco ONS 15454 SDH Procedure Guide. to view the audit trail
record. Any management interface (CTC, CTM, TL1) can access the audit trail logs.
The audit trail is stored in persistent memory and is not corrupted by processor switches, resets or
upgrades. However, if the TCC2/TCC2Ps are removed, the audit trail log is lost.
9.3.1 Audit Trail Log Entries
Table 9-4 contains the columns listed in Audit Trail window.
Audit trail records capture the following activities:
User—Name of the user performing the action
Host—Host from where the activity is logged
Device ID—IP address of the device involved in the activity
Application—Name of the application involved in the activity
Task—Name of the task involved in the activity (View a dialog, apply configuration and so on)
Connection Mode—Telnet, Console, SNMP
Category—Type of change; Hardware, Software, Configuration
Status—Status of the user action (Read, Initial, Successful, Timeout, Failed)
Time—Time of change
Table 9-4 Audit Trail Window Columns
Heading Explanation
Date Date when the action occurred
Num Incrementing count of actions
User User ID that initiated the action
P/F Pass/Fail (whether or not the action was executed)
Operation Action that was taken