HP 3PAR StoreServ 7400 2-node HP 3PAR Policy Server Administrator's G - Page 60

Audit Log Persistence, Policy-related Messages Sent to a SysLog Server

Page 60 highlights

• Agent evaluates a permission that has filters attached. When one or more filters are attached to a permission and a filter matches, the audit log displays a message that shows the asset name, action name, permission name, filter name, and the fact that there was a match. When none of the filters match and the default filter (the default access right) is applied, the audit log displays the asset name, action name, permission name, and then "default filter." If filter evaluation failed because the filter expression used unknown variables, the audit log reports, "Unknown symbol in filter expression for asset , action . Details: permission , filter , symbol=." If the filter expression has bad syntax, the audit log reports, "Invalid filter expression for asset , action . Details: permission , filter ." Audit Log Persistence The Agent gateway and Policy Agents queue all Policy Server-related auditing messages in their audit logs until they send them to Policy Server for processing. If the Policy Server is offline, the Agents persist the messages until they can communicate them to the Policy Server. If an Agent cannot communicate the messages to the Policy Server before the Agent's audit log has reached its maximum size, all new audit log entries are discarded. Policy-related Messages Sent to a SysLog Server Agents can send policy-related messages to a SysLog Server if they have been configured to do so. The configuration is done using Agent Builder, in the Policy Server Settings dialog box. The messages are NOT sent from Policy Server. Rather, the Agent collects the audit messages generated by its APMProxy component for delivery to the configured SysLog Server. Refer to the online help for Agent Builder for details. HP 3PAR Policy Server 6-10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

HP 3PAR Policy Server
6-10
Agent evaluates a permission that has filters attached. When one or more filters are attached to a
permission and a filter matches, the audit log displays a message that shows the asset name, action
name, permission name, filter name, and the fact that there was a match. When none of the filters
match and the default filter (the default access right) is applied, the audit log displays the asset
name, action name, permission name, and then "default filter."
If filter evaluation failed because the filter expression used unknown variables, the audit log reports,
"Unknown symbol in filter expression for asset <
name
>, action <
name
>. Details: permission
<
permission name
>, filter <
filter name
>, symbol=<
name
>."
If the filter expression has bad syntax, the audit log reports, "Invalid filter expression for asset
<
name
>, action <
name
>. Details: permission <
permission name
>, filter <
filter name
>."
Audit Log Persistence
The Agent gateway and Policy Agents queue all Policy Server-related auditing messages in their audit logs
until they send them to Policy Server for processing. If the Policy Server is offline, the Agents persist the
messages until they can communicate them to the Policy Server. If an Agent cannot communicate the
messages to the Policy Server before the Agent’s audit log has reached its maximum size, all new audit log
entries are discarded.
Policy-related Messages Sent to a SysLog Server
Agents can send policy-related messages to a SysLog Server if they have been configured to do so. The
configuration is done using Agent Builder, in the Policy Server Settings dialog box. The messages are NOT
sent from Policy Server. Rather, the Agent collects the audit messages generated by its APMProxy
component for delivery to the configured SysLog Server. Refer to the online help for Agent Builder for
details.