HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.2.x administrator guide (569 - Page 53

How to con an audit log for specific event classes, Shutting down switches and Directors

Page 53 highlights

How to configure an audit log for specific event classes 1. Connect to the switch from which you wish to generate an audit log and log in as admin. 2. Enter the auditCfg --class command, which defines the specific event classes to be filtered. switch:admin> auditcfg --class 2,4 Audit filter is configured. The auditCfg event class operands are identified in Table 6 3. Enter the auditCfg --enable command, which enables audit event logging based on the classes configured in step 2. switch:admin> auditcfg --enable Audit filter is enabled. To disable an audit event configuration, enter the auditCfg --disable command. 4. Enter the auditCfg --show command to view the filter configuration and confirm that the correct event classes are being audited, and the correct filter state appears (enabled or disabled). switch:admin> auditcfg --show Audit filter is enabled. 2-SECURITY 4-FIRMWARE To verify the audit event log setup, make a change affecting an enabled event class, and confirm that the remote host machine receives the audit event messages. The following example shows the SYSLOG (system message log) output for audit logging. Jun 2 08:33:04 [10.32.220.7.2.2] raslogd: AUDIT, 2006/06/02-15:25:53, [SULB-1003], INFO, FIRMWARE, root/root/NONE/console/CLI, ad_0/ras007_chassis, , Firmwarecommit has started. Jun 5 06:45:33 [10.32.220.70.2.2] raslogd: AUDIT, 2006/06/05-13:38:17, [CONF-1010], INFO, CONFIGURATION, root/root/NONE/ console/CLI, ad_0/ras070, , configDownload failed Jun 5 08:15:32 [10.32.248.73.2.2] raslogd: AUDIT, 2006/06/05-13:38:17, [SEC-1000], WARNING, SECURITY, JaneDoe/root/192.168.132.19/ telnet, Domain A/DoeSwitch, , Incorrect password during login attempt. Shutting down switches and Directors To avoid corrupting your file system, it is recommended that you perform graceful shutdowns of switches and Directors. To power off a Director gracefully (Prior to 5.1.0) For Directors running Fabric OS versions prior to 5.1.x, the following procedure describe how to gracefully shut down a Director: 1. Verify which CP is the active CP, and log in to the active CP using a Serial Console connection. 2. On the standby CP, set the slider switch to the off position, or eject the standby CP from the chassis. This disables the standby CP. 3. Enter the reboot command from the active CP. This will gracefully take down the system. 4. When you see the "Press escape within 4 seconds to enter boot interface" message, press ESC to suspend the active CP. 5. Power off the chassis by flipping both AC power switches to "0" (LEDs inside AC power switches should turn off). To maintain the ground connection, leave both power cords connected to the chassis and to an electrical outlet. For both switches and Directors running Fabric OS 5.1.0 and later, it is recommended that you use the following graceful shutdown procedures. Fabric OS 5.2.x administrator guide 53

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447

Fabric OS 5.2.x administrator guide
53
How to configure an audit log for specific event classes
1.
Connect to the switch from which you wish to generate an audit log and log in as admin.
2.
Enter the
auditCfg --class
command, which defines the specific event classes to be filtered.
The
auditCfg
event class operands are identified in
Table 6
3.
Enter the
auditCfg --enable
command, which enables audit event logging based on the classes
configured in
step 2
.
To disable an audit event configuration, enter the
auditCfg --disable
command.
4.
Enter the
auditCfg --show
command to view the filter configuration and confirm that the correct
event classes are being audited, and the correct filter state appears (enabled or disabled).
To verify the audit event log setup, make a change affecting an enabled event class, and confirm that
the remote host machine receives the audit event messages.
The following example shows the SYSLOG (system message log) output for audit logging.
Shutting down switches and Directors
To avoid corrupting your file system, it is recommended that you perform graceful shutdowns of switches
and Directors.
To power off a Director gracefully (Prior to 5.1.0)
For Directors running Fabric OS versions
prior
to 5.1.x, the following procedure describe how to gracefully
shut down a Director:
1.
Verify which CP is the active CP, and log in to the active CP using a Serial Console connection.
2.
On the standby CP, set the slider switch to the off position, or eject the standby CP from the chassis. This
disables the standby CP.
3.
Enter the
reboot
command from the active CP. This will gracefully take down the system.
4.
When you see the “Press escape within 4 seconds to enter boot interface” message, press ESC to
suspend the active CP.
5.
Power off the chassis by flipping both AC power switches to “0” (LEDs inside AC power switches should
turn off). To maintain the ground connection, leave both power cords connected to the chassis and to
an electrical outlet.
For both switches and Directors running Fabric OS 5.1.0 and later, it is recommended that you use the
following graceful shutdown procedures.
switch:admin>
auditcfg --class 2,4
Audit filter is configured.
switch:admin>
auditcfg --enable
Audit filter is enabled.
switch:admin>
auditcfg --show
Audit filter is enabled.
2-SECURITY
4-FIRMWARE
Jun
2 08:33:04 [10.32.220.7.2.2] raslogd: AUDIT, 2006/06/02-15:25:53,
[SULB-1003], INFO, FIRMWARE, root/root/NONE/console/CLI, ad_0/ras007_chassis, ,
Firmwarecommit has started.
Jun 5 06:45:33 [10.32.220.70.2.2] raslogd: AUDIT, 2006/06/05-13:38:17,
[CONF-1010], INFO, CONFIGURATION, root/root/NONE/
console/CLI, ad_0/ras070, , configDownload failed
Jun 5 08:15:32 [10.32.248.73.2.2] raslogd: AUDIT, 2006/06/05-13:38:17,
[SEC-1000], WARNING, SECURITY, JaneDoe/root/192.168.132.19/
telnet, Domain A/DoeSwitch, , Incorrect password during login attempt.