The output audit log is composed of the syslog header and the message.
The output format of the syslog header depends on the operating system environment settings.
For example, when rsyslogd is used, specifying $ActionFileDefaultTemplate RSYSLOG_SyslogProtocol23Format in the /etc/rsyslog.conf file outputs the audit log in a format that supports RFC5424.
- The following content is output in the syslog header:
priority
date-and-time
host-name
program-name
process-ID
The following shows the format of message-section and explains its contents.
- The format of message-section:
common-identifier,common-specification-revision-number,serial-number,message-ID,date-and-time,entity-affected,location-affected,audit-event-type,audit-event-result,subject-ID-for-audit-event-result,hardware-identification-information,location-information,location-identification-information,FQDN,redundancy-identification-information,agent-information,host-sending-request,port-number-sending-request,host-receiving-request,port-number-receiving-request,common-operation-ID,log-type-information,application-identification-information,reserved-area,message-text
Up to 950 bytes of text can be displayed for each message-section.
Item# |
Explanation |
|---|---|
Common identifier |
Fixed to CELFSS |
Common specification revision number |
Fixed to 1.1 |
Serial number |
Serial number of the audit log message |
Message ID |
Message ID in KAPL15nnn-l format |
Date and time |
The date and time when the message was output. This item is output in the following format: yyyy-mm-ddThh:mm:ss.s time-zone |
Entity affected |
Component or process name |
Location affected |
Host name |
Audit event type |
Event type |
Audit event result |
Event result |
Subject ID for audit event result |
Depending on the event, an account ID, process ID, or IP address is output. |
Hardware identification information |
Hardware model name or serial number |
Location information |
Hardware component identification information |
Location identification information |
Location identification information |
FQDN |
Fully qualified domain name |
Redundancy identification information |
Redundancy identification information |
Agent information |
Agent information |
Host sending request |
Name of the host sending a request |
Port number sending request |
Number of the port sending a request |
Host receiving request |
Name of the host receiving a request |
Port number receiving request |
Number of the port receiving a request |
Common operation ID |
Operation serial number in the program |
Log type information |
Fixed to BasicLog |
Application identification information |
Program identification information |
Reserved area |
This field is reserved. No data is output here. |
Message text |
Data related to the audit event is output. |
#: The output of this item depends on the audit event.
- Example of the message section for the audit event An attempt to display HDLM management-target information was successful:
-
CELFSS,1.1,0,KAPL15109-I, 2008-04-09T10:18:40.6+09:00,HDLMCommand,hostname=moon,ConfigurationAccess,Success,uid=root,,,,,,,,,,,,,,,"Information about HDLM-management targets was successfully displayed. Command Line = /opt/DynamicLinkManager/bin/dlnkmgr view -path "