Cisco ISR 4000 Family Routers Administrator Guidance
Page
48
of
66
Requirement
Auditable Events
Additional
Audit Record
Contents
Sample Record
LOGIN_FAILED: Login failed [user:
anonymous]
[Source:
100.1.1.5]
[localport:
22]
[Reason:
Login
Authentication Failed] at 11:19:06 UTC
Mon Jun 18 2012
Establishment of a SSH session
IP address of remote host
Jun
18
2012
11:31:35
UTC:
%SEC_LOGIN-5-LOGIN_SUCCESS:
Login Success [user: ranger] [Source:
100.1.1.5] [localport: 22] at 11:31:35
UTC Mon Jun 18 2012
Feb
8
06:47:17.041:
%SSH-5-
SSH2_CLOSE: SSH2 Session from
1.1.1.1 (tty = 0) for user 'cisco' using
crypto cipher 'aes256-cbc', hmac 'hmac-
sha1-96' closed
FIA_UIA_EXT.1
All use of the
identification and
authentication
mechanism.
Provided user
identity, origin
of the attempt
(e.g.,
IP
address).
See Audit events in FIA_UAU_EXT.2
FIA_UAU_EXT.2
All use of the
authentication
mechanism.
Origin of the
attempt (e.g.,
IP address).
Login as an administrative user at the
console
Username: auditperson
Password:
000278:
*Apr
23
07:11:56:
%SEC_LOGIN-5-LOGIN_SUCCESS:
Login
Success
[user:
auditperson]
[Source: 0.0.0.0] [localport: 0] at
07:11:56 UTC Thu Apr 23 2009?
Failed login via the console does not
allow any actions
Username: auditperson
Password:
% Authentication failed
Username:
000254:
*Apr
26
00:45:43.340:
%SEC_LOGIN-4-LOGIN_FAILED: