HP XP20000/XP24000 HP StorageWorks XP24000/XP20000 Audit Log Reference Guide ( - Page 17

Storing Audit Logs, Set Syslog Server Operation

Page 17 highlights

10. Confirm that the syslog server is receiving the log of syslog server setting when the setting operation is completed. AuditLog is the function name of the log and Set Syslog Server is the operation name (see "Set Syslog Server Operation" (page 45)). If the log is not received by the syslog server, verify that the IP address and the port number set matches with the IP address and the port number of the syslog server. If the IP address and the port number matches, check the syslog server setting. See the users manual of the syslog server for more details on syslog server settings. Figure 2 Syslog Window Storing Audit Logs To store audit logs, you can either to temporarily store audit logs in a system disk before storing the logs in the SVP, or store audit logs directly in the SVP. To keep track of commands sent from hosts, HP recommends that you temporarily store audit logs in a system disk before storing the logs in the SVP. Audit logs are transferred and stored in the SVP. However, audit logs might get lost if the SVP is not working due to a failure, because the SVP cannot receive the transferred audit logs. You can temporarily store logs in a system disk so that you can reduce the risk of losing audit logs. The audit logs stored in the system disk will be eventually stored in the SVP. Only the storage administrator can configure how to store audit logs, and the Audit Log Administrator Role needs to be set to Modify. Make sure that the storage administrator has created a system disk to store audit logs temporarily before storing the logs in the SVP. To configure how to store audit logs: 1. Log on as a storage administrator and open the Remote Web Console main window. 2. Change to Modify mode. 3. Click Go - Security - Audit Log Setting in the menu bar of the Remote Web Console main window. The Audit Log Setting window (see Figure 3 (page 18)) displays. Storing Audit Logs 17

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279

10. Confirm that the syslog server is receiving the log of syslog server setting when the setting
operation is completed. AuditLog is the function name of the log and Set Syslog Server is the
operation name (see
“Set Syslog Server Operation” (page 45)
).
If the log is not received by the syslog server, verify that the IP address and the port number
set matches with the IP address and the port number of the syslog server. If the IP address and
the port number matches, check the syslog server setting. See the users manual of the syslog
server for more details on syslog server settings.
Figure 2 Syslog Window
Storing Audit Logs
To store audit logs, you can either to temporarily store audit logs in a system disk before storing
the logs in the SVP, or store audit logs directly in the SVP. To keep track of commands sent from
hosts, HP recommends that you temporarily store audit logs in a system disk before storing the logs
in the SVP.
Audit logs are transferred and stored in the SVP. However, audit logs might get lost if the SVP is
not working due to a failure, because the SVP cannot receive the transferred audit logs. You can
temporarily store logs in a system disk so that you can reduce the risk of losing audit logs. The
audit logs stored in the system disk will be eventually stored in the SVP.
Only the storage administrator can configure how to store audit logs, and the
Audit Log
Administrator Role
needs to be set to
Modify
. Make sure that the storage administrator has created
a system disk to store audit logs temporarily before storing the logs in the SVP.
To configure how to store audit logs:
1.
Log on as a storage administrator and open the Remote Web Console main window.
2.
Change to
Modify
mode.
3.
Click
Go – Security – Audit Log Setting
in the menu bar of the Remote Web Console main
window. The Audit Log Setting window (see
Figure 3 (page 18)
) displays.
Storing Audit Logs
17