Specifications
12-5
VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring
78-13274-01
Chapter 12 Filterable Event Log
Monitoring | Filterable Event Log
Event Time
The time of the event: hour:minute:second.millisecond. The hour is based on a 24-hour clock. For
example, 14:37:06.680 identifies an event that occurred at 2:37:06.680 PM.
Event Severity
The severity level of the event; for example: SEV=4 identifies an event of severity level 4. For an
explanation of event severity levels, refer to VPN 3000 Series Concentrator Reference Volume 1:
Configuration.
Event Class / Number
The class, or source, of the event, and the internal reference number associated with the specific event
within the event class. For example:
HTTP/47 identifies that an administrator logged in to the VPN
Concentrator using HTTP to connect to the Manager. For a description of event classes, refer to VPN
3000 Series Concentrator Reference Volume 1: Configuration. The internal reference number assists
Cisco support personnel if they need to examine a log file.
Event Repeat
The number of times that this specific event has occurred since the VPN Concentrator was last booted
or reset. For example, RPT=17 indicates that this is the seventeenth occurrence of this specific event.
Event IP Address
The IP address of the client or host associated with this event. Only certain events have this field. For
tunnel-related events, this is typically the “outer” or tunnel endpoint address. In the Event log format
example, 10.10.1.35 is the IP address of the host PC from which admin logged in using the Manager.
Event String
The string, or message, that describes the specific event. Each event class comprises many possible
events, and the string gives a brief description. Event strings usually do not exceed 80 characters. In the
Event log format example, “
New administrator login: admin” describes the event.