Collecting audit log data

Dynamic Link Manager (for Linux®) User Guide

Version
9.0.x
Audience
anonymous
Part Number
MK-92DLM113-64
ft:lastEdition
2025-11-06

HDLM and other Hitachi storage-related products provide an audit log function so that compliance with regulations, security evaluation standards, and industry-specific standards can be shown to auditors and evaluators. The following table describes the categories of audit log data that Hitachi storage-related products can collect.

Table. Categories of audit log data that can be collected

Category

Explanation

StartStop

An event indicating the startup or termination of hardware or software, including:

  • OS startup and termination

  • Startup and termination of hardware components (including micro-program)

  • Startup and termination of software running on storage systems, software running on SVPs (service processors), and Hitachi Command Suite products

Failure

An abnormal hardware or software event, including:

  • Hardware errors

  • Software errors (such as memory errors)

LinkStatus

An event indicating the linkage status between devices:

  • Link up or link down

ExternalService

An event indicating the result of communication between a Hitachi storage-related product and an external service, including:

  • Communication with a RADIUS server, LDAP server, NTP server, or DNS server

  • Communication with the management server (SNMP)

Authentication

An event indicating that a connection or authentication attempt made by a device, administrator, or end-user has succeeded or failed, including:

  • FC login

  • Device authentication (FC-SP authentication, iSCSI login authentication, or SSL server/client authentication)

  • Administrator or end-user authentication

AccessControl

An event indicating that a resource access attempt made by a device, administrator, or end-user has succeeded or failed, including:

  • Device access control

  • Administrator or end-user access control

ContentAccess

An event indicating that an attempt to access critical data has succeeded or failed, including:

  • Access to a critical file on a NAS or content access when HTTP is supported

  • Access to the audit log file

ConfigurationAccess

An event indicating that a permitted operation performed by the administrator has terminated normally or failed, including:

  • Viewing or updating configuration information

  • Updating account settings, such as adding and deleting accounts

  • Setting up security

  • Viewing or updating audit log settings

Maintenance

An event indicating that a maintenance operation has terminated normally or failed, including:

  • Adding or removing hardware components

  • Adding or removing software components

AnomalyEvent

An event indicating an abnormal state such as exceeding a threshold, including:

  • Exceeding a network traffic threshold

  • Exceeding a CPU load threshold

  • Reporting that the temporary audit log data saved internally is close to its maximum size limit or that the audit log files have wrapped back around to the beginning

An event indicating an occurrence of abnormal communication, including:

  • A SYN flood attack or protocol violation for a normally used port

  • Access to an unused port (such as port scanning)

The categories of audit log data that can be collected differ depending on the product. The following sections explain only the categories of audit log data that can be collected by HDLM. For the categories of audit log data that can be collected by a product other than HDLM, see the corresponding product manual.