User guide

Syslog message formats Chapter 4: Reference information
4-74
phn-2513_004v000 (Oct 2012)
Event messages
Event messages are listed in Table 201. Definition of abbreviations:
SC = ";"
SP = " "
This is an example of an event message:
PTP800: event; auth_login; web user=MarkT; from=169.254.1.1; port=80;
connection=HTTP; authentication=local;
Table 201 Event messages
Facility Severity Identifier Message content
security(4) warning(4) auth_idle "Web user=" user-name SC SP "from="
IP-address SC SP "port=" port-number
SC SP "connection=" ("HTTP" |
"HTTPS") SC SP "authentication="
("local" | "RADIUS") SC
security(4) info(6) auth_login
security(4) warning(4) auth_login_failed
security(4) warning(4) auth_login_locked
security(4) info(6) auth_logout
kernel(0) warning(4) cold_start "PTP wireless bridge has reinitialized,
reason=" reset-reason SC
security(4) warning(4) License_update "License Key updated" SC
syslog(5) warning(4) log_full "Syslog local flash log is 90% full" SC
syslog(5) warning(4) log_wrap "Syslog local flash log has wrapped" SC
local6(22) warning(4) protection_switch "Protection switch, reason="
protectionSwitchCause SC
security(4) info(6) radius_auth "RADIUS user=" user-name SC SP
"server " ("1" | "2") " at " IP-address SP
"succeeded" SC
security(4) warning(4) radius_auth_fail "RADIUS user=" user-name SC SP
"server " ("1" | "2") " at " IP-address SP
("failed" | "succeeded" | "failed (no
response)") SC
security(4) alert(1) resource_low "Potential DoS attack on packet ingress
" ("warning" | "cleared") SC