Cisco ISR 4000 Family Routers Administrator Guidance
Page
50
of
66
Requirement
Auditable Events
Additional
Audit Record
Contents
Sample Record
Aug
3
19:10:18.621:
%PKI-3-
CERTIFICATE_REVOKED: Certificate
chain
validation
has
failed.
The
certificate (SN: 04) is revoked
FMT_MOF.1(1)/Ad
minAct
Modification
of
the behaviour of
the TSF.
None.
Feb 17 2013 16:34:02: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged
command:logging informational
FMT_MOF.1(1)/Tr
usted Update
Any attempt to
initiate a manual
update
None.
*Jul 10 11:04:09.179: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:cisco logged command:upgrade
FMT_MTD.1
All management
activities of TSF
data
None.
Feb 17 2013 16:34:02: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged
command:logging informational
FMT_MTD.1/Admi
nAct
Modification,
deletion,
generation/import
of cryptographic
keys.
None.
Feb 17 2013 16:37:27: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged
command:crypto key zeroize
FPF_RUL_EXT.1
Application
of
rules
configured
with the ‘log’
operation
Source
and
destination
addresses
Source
and
destination
ports
Transport
Layer Protocol
TOE Interface
Jan 21 2013 11:29:16 UTC: %SEC-6-
IPACCESSLOGP: list 111 permitted tcp
21.0.0.20(3333) -> 21.0.0.1(21), 1 packet
Jan 21 2013 11:43:45 UTC: %SEC-6-
IPACCESSLOGP: list 111 denied tcp
21.0.0.20(0) -> 21.0.0.1(21), 1 packet
Indication
of
packets
dropped
due to too much
network traffic
TOE interface
that is unable
to
process
packets
*May 6 04:04:28.279: %HA_EM-6-
LOG: test2: value GigabitEthernet0/2
output_packets_dropped increased from
1058406890 to 1061078215