Audit log configuration – Brocade Network OS NETCONF Operations Guide v4.1.1 User Manual
Page 77

Network OS NETCONF Operations Guide
45
53-1003231-02
Audit log configuration
3
Audit log configuration
Audit log messages contain user information such as login name and login IP address. The audit
log’s purpose is to enable tracking of important user-originated events in the cluster; this is in
contrast to RASlog messages, which are primarily used for abnormal or error-related events.
When an audit log message is generated on a switch, it is forwarded to the syslog server. To limit
the audit log messages to the syslog server and facilitate monitoring of the audit log messages,
three audit log classes are defined: FIRMWARE, SECURITY, and CONFIGURATION.
You must enable the audit log class to generate the audit log messages for that class. The classes
are enabled by default. To enable or disable the auditing of these classes, perform the following
steps.
1. Issue the
urn:brocade.com:mgmt:brocade-ras namespace.
2. Under the
3. Under the
or disable.
4. Under each
you want to enable or disable.
5. To disable a class, include the delete operation in the
The following example enables SECURITY and WARNING messages, but disables CONFIGURATION
messages.
operation="delete">