Connectivity Guide

Table Of Contents
Display audit log entries in EXEC mode. By default, 24 entries are displayed, starting with the oldest event. Enter reverse
to display entries starting with the most recent events. You can change the number of entries displayed.
show logging audit [reverse] [number]
Clear audit log
Clear all events in the audit log in CONFIGURATION mode.
clear logging audit
Example
OS10(config)# logging audit enable
OS10(config)# exit
OS10# show logging audit 4
<14>1 2019-02-14T13:15:06.283337+00:00 OS10 audispd - - - Node.1-Unit.1:PRI [audit],
Dell EMC (OS10) node=OS10 type=USER_END msg=audit(1550150106.277:597): pid=7908 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:session_close acct="admin" exe="/bin/su"
hostname=? addr=? terminal=??? res=success'
<110>1 2019-02-14T13:15:16.331515+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'crypto security-profile mltestprofile' - success
<110>1 2019-02-14T13:15:21.794529+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:16:05.882555+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'exit' - success
OS10# show logging audit reverse 4
<110>1 2019-02-14T13:16:05.882555+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:15:21.794529+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:15:16.331515+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit],
User admin on console used cmd: 'crypto security-profile mltestprofile' - success
<14>1 2019-02-14T13:15:06.283337+00:00 OS10 audispd - - - Node.1-Unit.1:PRI [audit],
Dell EMC (OS10) node=OS10 type=USER_END msg=audit(1550150106.277:597): pid=7908 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:session_close acct="admin" exe="/bin/su"
hostname=? addr=? terminal=??? res=success'OS10# show logging audit reverse 10
Security commands
aaa accounting
Enables AAA accounting.
Syntax
aaa accounting commands all {console | default} {start-stop | stop-only |
none} [logging] [group tacacs+]
Parameters
commands all Record all user-entered commands. This option is not supported for RADIUS
accounting.
console Record all user authentication and logins or all user-entered commands in OS10 sessions
on console connections.
default Record all user authentication and logins or all user-entered commands in OS10 sessions
on remote connections; for example, Telnet and SSH.
start-stop Send a start notice when a process begins, and a stop notice when the process
ends.
stop-only Send only a stop notice when a process ends.
none No accounting notices are sent.
logging Logs all accounting notices in syslog.
group tacacs+ Logs all accounting notices on the first reachable TACACS+ server.
Default AAA accounting is disabled.
Security 765