HP StorageWorks XP Command View Advanced Edition Software 6.4 Server Administrator Guide for Device Manager and Provisioning Manager (web) (T1780-96341, July 2010)

Table Of Contents
Setting up logs and alerts
96
Table 6-1 Categories and descriptions
Category Description
AccessControl
Events indicating that a device, administrator, or end user
succeeded or failed in gaining access to resources:
Access control for devices
Access control for the administrator or end users
ContentAccess
Events indicating that attempts to access important data
succeeded or failed:
Access to important files on NAS or to contents when HTTP is
supported
Access to audit log files
ConfigurationAccess
Events indicating that the administrator succeeded or failed in
performing an allowed operation:
Reference or update of the configuration information
Update of account settings including addition or deletion of
accounts
Security configuration
Reference or update of audit log settings
Maintenance
Events indicating that a performed maintenance operation
succeeded or failed:
Addition or deletion of hardware components
Addition or deletion of software components
Events indicating that an anomaly, such as a threshold being
exceeded, occurred:
A network traffic threshold was exceeded
A CPU load threshold was exceeded
Pre-notification that a limit is being reached or a wraparound
occurred for audit log data temporarily saved internally
AnomalyEvent
Events indicating that abnormal communication occurred:
SYN flood attacks to a regularly used port, or protocol
violations
Access to an unused port (such as port scanning)
Different products generate different types of audit log data. The following sections describe the
audit log data that can be generated by Device Manager and XP Provisioning Manager. For details
on the audit log data generated by other products, see the manual for the corresponding product.
For details on the contents of the output audit log data, see section
10-4 .
6-2-1 Audit events and categories of information output to
audit logs
In Device Manager, the following categories of audit events are output to audit logs:
StartStop
Authentication
ConfigurationAccess
Each audit event is assigned a severity level. You can filter audit log data to be output according to
the severity levels of events.
Table 6-2 to Table 6-4 list the audit events that are output to audit logs in Device Manager.