HP Hitachi Dynamic Link Manager Software User Manual
Page 57
Category
Explanation
AnomalyEvent
An event indicating an abnormal state such as exceeding a
threshold, including:
•
Exceeding a network traffic threshold
•
Exceeding a CPU load threshold
•
Reporting that the temporary audit log data saved
internally is close to its maximum size limit or that the
audit log files have wrapped back around to the
beginning
An event indicating an occurrence of abnormal
communication, including:
•
A SYN flood attack or protocol violation for a normally
used port
•
Access to an unused port (such as port scanning)
The categories of audit log data that can be collected differ depending on the
product. The following sections explain only the categories of audit log data
that can be collected by HDLM. For the categories of audit log data that can
be collected by a product other than HDLM, see the corresponding product
manual.
Categories and Audit Events that HDLM Can Output to the Audit Log
The following table lists and explains the categories and audit events that
HDLM can output to the audit log. The severity is also indicated for each audit
event.
Table 2-10 Categories and Audit Events That Can Be Output to the Audit
Log
Category
Explanation
Audit event
Severity
#1
Message ID
StartStop
Startup and
termination of
the software
Startup of the
HDLM manager
was successful.
6
KAPL15401-I
Startup of the
HDLM manager
failed.
4
KAPL15402-W
The HDLM
manager stopped.
6
KAPL15403-I
Startup of the
DLMgetras utility
6
KAPL15060-I
Termination of
the DLMgetras
utility
#2
6
KAPL15061-I
HDLM Functions
2-37
Hitachi Dynamic Link Manager User Guide (for Windows(R))