Hitachi Dynamic Link Manager Software Users Guide for Linux (6.6) (HIT5203-96005, November 2011)
Audit Log Data Formats
The following describes the format of audit log data:
Format of audit log data output to syslog:
¢
priority
¢
date-and-time
¢
host-name
¢
program-name
¢
[process-ID]
¢
message-section
The following shows the format of message-section and explains its contents.
The format of message-section:
common-identifier , common-specification-revision-number , serial-
number , message-ID , date-and-time , entity-affected , location-
affected , audit-event-type , audit-event-result , subject-ID-for-audit-
event-result , hardware-identification-information , location-
information , location-identification-information , FQDN , redundancy-
identification-information , agent-information , host-sending-request ,
port-number-sending-request , host-receiving-request , port-number-
receiving-request , common-operation-ID , log-type-information ,
application-identification-information , reserved-area , message-text
Up to 950 bytes of text can be displayed for each message-section.
Table 2-13 Items Output in the Message Section
Item
#
Explanation
Common identifier Fixed to CELFSS
Common specification
revision number
Fixed to 1.1
Serial number Serial number of the audit log message
Message ID Message ID in KAPL15nnn-l format
Date and time The date and time when the message was output. This item is
output in the following format:
yyyy - mm - ddThh : mm : ss . s time-zone
Entity affected Component or process name
Location affected Host name
Audit event type Event type
Audit event result Event result
Subject ID for audit
event result
Depending on the event, an account ID, process ID, or IP
address is output.
2-42
HDLM Functions
Hitachi Dynamic Link Manager User Guide (for Linux(R))