Technical data

10 Network OS Message Reference
53-1002489-01
Viewing, clearing, and configuring Audit messages
1
Viewing, clearing, and configuring Audit messages
This section provides information on viewing, clearing, and configuring the Audit log messages.
Displaying the Audit messages
To display the saved Audit messages, perform the following steps.
1. Log in to the switch as admin.
2. Enter the show logging auditlog command at the command line.
switch# show logging auditlog
0 AUDIT,2011/08/26-07:50:42 (GMT), [SEC-3034], INFO, SECURITY,
NONE/root/NONE/None/CLI,, VDX6720-24, Event: AAA Authentication Login Mode
Configuration, Status: success, Info: Authentication configuration changed
from Local Only to Local Only.
1 AUDIT,2011/08/26-07:51:29 (GMT), [RAS-2001], INFO, SYSTEM,
NONE/root/NONE/None/CLI,, switch, Audit message log is enabled.
2 AUDIT,2011/08/26-07:51:29 (GMT), [RAS-2003], INFO, SYSTEM,
NONE/root/NONE/None/CLI,, switch, Audit message class configuration has been
changed to 2,6,4,.
3 AUDIT,2011/08/26-07:51:32 (GMT), [DCM-2001], INFO, DCMCFG,
root/none/127.0.0.1/rpc/cli,, VDX6720-24, Event: noscli start, Status:
success, Info: Successful login attempt through console from 127.0.0.1.
4 AUDIT,2011/08/26-07:51:34 (GMT), [DCM-2001], INFO, DCMCFG,
admin/admin/127.0.0.1/rpc/cli,, VDX6720-24, Event: noscli start, Status:
success, Info: Successful login attempt through console from 127.0.0.1.
5 AUDIT,2011/08/26-07:51:36 (GMT), [DCM-2002], INFO, DCMCFG,
admin/admin/127.0.0.1/rpc/cli,, VDX6720-24, Event: noscli exit, Status:
success, Info: Successful logout by user [admin].
Clearing the Audit messages
To clear the Audit log messages for a particular switch instance, perform the following steps.
1. Log in to the switch as admin.
2. Execute the clear logging auditlog command to clear all messages on the switch memory.
Configuring event auditing
The audit log classes SECURITY, CONFIGURATION, and FIRMWARE are enabled by default. You can
enable or disable auditing of these classes using the logging auditlog class class command.
To configure and verify the event auditing, perform the following steps.
1. Execute the configure terminal command to access the global configuration level of the CLI.
switch# configure terminal
Entering configuration mode terminal