HP X Unified Security Platform Series Bedienungsanleitung Seite 116

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 333
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 115
Chapter 5 Events: Logs, Traffic Streams, Reports
100 X Family LSM User’s Guide V 2.5.1
Audit Log
The audit log tracks user activity that may have security implications, including user attempts
(successful and unsuccessful) to do the following:
Change user information
Change IPS, firewall, routing or network configuration
Gain access to controlled areas (including the audit log)
Update system software and attack protection filter packages
•Change filter settings
To maintain a complete history of entries and provide a backup, you can configure the X family device
to send Audit Block Log entries to a remote syslog server from the Syslog Servers page. For details, see
the
Syslog Servers” on page 242.
An Audit log entry contains the following fields:
Source Address The source address of the triggering traffic
Dest Address The destination address of the triggering traffic
Packet Trace Details if a packet trace is available
Hit Count Details how many packets have been detected
Table 5–1: Alert Log Field Descriptions (Continued)
Column Description
Note Only users with Super-user access level can view, print, reset, and
download the audit log.
Table 5–2: Audit Log Field Descriptions
Column Description
Log ID A system-assigned Log ID number
Date and Time A date and time stamp in the format year-month-date hour:minute:second
Username The login name of the user performing the action. The user listed for an event
may include SMS, SYS, and CLI. These entries are automatically generated when
one of these applications performs an action.
Access Level The access-level of the user performing the action
IP Address The IP address from which the user connected to perform the action
Interface The interface with which the user logged in (either WEB for the LSM or CLI for
the Command Line Interface)
Seitenansicht 115
1 2 ... 111 112 113 114 115 116 117 118 119 120 121 ... 332 333

Kommentare zu diesen Handbüchern

Keine Kommentare