HP XP20000/XP24000 HP StorageWorks XP24000/XP20000 Audit Log Reference Guide ( - Page 24

Table 4 Items in the Syslog File

Page 24 highlights

Table 4 Items in the Syslog File (continued) No. Item Description 7 Message identification The serial number of the syslog header information. information 8 Message ID. Not displayed because it is not used. 9 Date, time#21 The date, time and the time difference between UTC (Coordinated Universal Time) in the format of YYYY-MM-DD-Thh:mm:ss.s hh:mm (YYYY: year, MM: month, DD: day, hh: hour, mm: minute, ss.s: second, hh: hours of the time difference and mm: minute of the time difference) Z is displayed instead of hh:mm when there is no time difference between UTC, such as 2005-12-26T:23:06:58.0Z. The displayed format for second ss.s represents one decimal place. 10 Detection entity 11 Detected location 12 Type of audit event The detection entity identification character (Storage). The host name (SVP). The category name of the event as described in the following example: • Authentication. iSCSI login or authentication of RMI (Remote Method Invocation) • ConfigurationAccess. Setting from Remote Web Console, SVP, or host. • AnomalyEvent. Reached the maximum of the audit log, etc. • Maintenance. SVP maintenance. 13 Result of the audit event The result of the audit event: • Success: Normal end. The operation has ended normally. • Failed: Error (xxxx-yyyy). The operation has ended abnormally. • Failed: Warning (xxxx-yyyy). The operation has partly ended abnormally or was canceled during the operation. Error codes are described as xxxx-yyyyy. SVP operations or commands from the host do not output error codes. 14 Subject identification The user name in the format of uid=user name. information • When the category name is AnomalyEvent, or the DKA Encryption License Key is created, is output. • is output for SVP operation. • is output for commands from host. 15 Hardware identification The ID (R600) to identify the model name of the product and the serial number divided information by a colon. 16 Generated location Not displayed because it is not used. information 17 Related information The location identification name set by the user in the Syslog window. 18 FQDN. Not displayed because it is not used. 19 Redundant identification information. Not displayed because it is not used. 20 Agent information Not displayed because it is not used. 24 Audit Log File Format

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279

Table 4 Items in the Syslog File
(continued)
Description
Item
No.
The serial number of the syslog header information.
Message identification
information
7
Message ID. Not displayed because it is not used.
8
The date, time and the time difference between UTC (Coordinated Universal Time)
in the format of YYYY-MM-DD-Thh:mm:ss.s
hh
:
mm
(YYYY: year, MM: month, DD:
day, hh: hour, mm: minute, ss.s: second,
hh
: hours of the time difference and
mm
:
minute of the time difference)
Z is displayed instead of
hh
:
mm
when there is no time difference between UTC,
such as 2005-12-26T:23:06:58.0Z.
The displayed format for second
ss.s
represents one decimal place.
Date, time#2
1
9
The detection entity identification character (Storage).
Detection entity
10
The host name (SVP).
Detected location
11
The category name of the event as described in the following example:
Authentication. iSCSI login or authentication of RMI (Remote Method Invocation)
ConfigurationAccess. Setting from Remote Web Console, SVP, or host.
AnomalyEvent. Reached the maximum of the audit log, etc.
Maintenance. SVP maintenance.
Type of audit event
12
The result of the audit event:
Success: Normal end. The operation has ended normally.
Failed: Error (xxxx-yyyy). The operation has ended abnormally.
Failed: Warning (xxxx-yyyy). The operation has partly ended abnormally or was
canceled during the operation.
Error codes are described as xxxx-yyyyy. SVP operations or commands from the
host do not output error codes.
Result of the audit event
13
The user name in the format of
uid=user name
.
When the category name is AnomalyEvent, or the DKA Encryption License Key is
created,
<system>
is output.
<DKCMaintenance>
is output for SVP operation.
<Host>
is output for commands from host.
Subject identification
information
14
The ID (R600) to identify the model name of the product and the serial number divided
by a colon.
Hardware identification
information
15
Not displayed because it is not used.
Generated location
information
16
The location identification name set by the user in the
Syslog
window.
Related information
17
FQDN. Not displayed because it is not used.
18
Redundant identification information. Not displayed because it is not used.
19
Not displayed because it is not used.
Agent information
20
24
Audit Log File Format