The security log contains security events and information. RBAC restricts access to audit and security logs based on the CLI sessions’ user
roles. The types of information in this log consist of the following:
•
Establishment of secure traffic flows, such as SSH.
•
Violations on secure flows or certificate issues.
•
Adding and deleting of users.
•
User access and configuration changes to the security and crypto parameters (not the key information but the crypto configuration)
Important Points to Remember
When you enabled RBAC and extended logging:
•
Only the system administrator user role can execute this command.
•
The system administrator and system security administrator user roles can view security events and system events.
•
The system administrator user roles can view audit, security, and system events.
•
Only the system administrator and security administrator user roles can view security logs.
•
The network administrator and network operator user roles can view system events.
NOTE:
If extended logging is disabled, you can only view system events, regardless of RBAC user role.
Example of Enabling Audit and Security Logs
Dell(conf)#logging extended
Displaying Audit and Security Logs
To display audit logs, use the
show logging auditlog
command in Exec mode. To view these logs, you must first enable the logging
extended command. Only the RBAC system administrator user role can view the audit logs. Only the RBAC security administrator and
system administrator user role can view the security logs. If extended logging is disabled, you can only view system events, regardless of
RBAC user role. To view security logs, use the
show logging
command.
Example of the
show logging auditlog
Command
For information about the logging extended command, see
Enabling Audit and Security Logs
Dell#show logging auditlog
May 12 12:20:25: Dell#: %CLI-6-logging extended by admin from vty0 (10.14.1.98)
May 12 12:20:42: Dell#: %CLI-6-configure terminal by admin from vty0 (10.14.1.98)
May 12 12:20:42: Dell#: %CLI-6-service timestamps log datetime by admin from vty0 (10.14.1.98)
Example of the
show logging
Command for Security
For information about the logging extended command, see
Enabling Audit and Security Logs
Dell#show logging
Jun 10 04:23:40: %STKUNIT0-M:CP
%SEC-5-LOGIN_SUCCESS
: Login successful for user admin on line
vty0 ( 10.14.1.91 )
Clearing Audit Logs
To clear audit logs, use the
clear logging auditlog
command in Exec mode. When RBAC is enabled, only the system administrator
user role can issue this command.
Example of the clear logging auditlog
Command
Dell# clear logging auditlog
Management
65
Summary of Contents for S3048-ON
Page 1: ...Dell Configuration Guide for the S3048 ON System 9 11 2 5 ...
Page 137: ...0 Gi 1 1 Gi 1 2 rx Flow N A N A 0 0 No N A N A yes Access Control Lists ACLs 137 ...
Page 142: ...Figure 10 BFD Three Way Handshake State Changes 142 Bidirectional Forwarding Detection BFD ...
Page 241: ...Dell Control Plane Policing CoPP 241 ...
Page 287: ... RPM Synchronization GARP VLAN Registration Protocol GVRP 287 ...
Page 428: ...Figure 53 Inspecting the LAG Configuration 428 Link Aggregation Control Protocol LACP ...
Page 477: ...Figure 73 Configuring Interfaces for MSDP Multicast Source Discovery Protocol MSDP 477 ...
Page 478: ...Figure 74 Configuring OSPF and BGP for MSDP 478 Multicast Source Discovery Protocol MSDP ...
Page 483: ...Figure 77 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 483 ...
Page 484: ...Figure 78 MSDP Default Peer Scenario 3 484 Multicast Source Discovery Protocol MSDP ...
Page 745: ...Figure 104 Single and Double Tag TPID Match Service Provider Bridging 745 ...
Page 746: ...Figure 105 Single and Double Tag First byte TPID Match 746 Service Provider Bridging ...