Weird entries in audit log

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Post Reply
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Weird entries in audit log

Post by BanditBBS »

So one of my customers is a public company and has to link all audit log entries to a change control. While reconciling Novembers, we can't figure out what these entries are for, and why they showed up....
Audit log.png
Nobody was performing a change at that time, it looks like in the early afternoon, cfg files for all config wizards appeared in the import folder and were imported into XI.
You do not have the required permissions to view the files attached to this post.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
User avatar
jmichaelson
Posts: 335
Joined: Wed Aug 23, 2023 1:02 pm

Re: Weird entries in audit log

Post by jmichaelson »

Having a look through things, those messages come from ccm_import.php, ccm_import.php is executed from reconfigure_nagios.sh, and when core config is imported within Nagios XI. Is there also an audit log entry akin to "Applied a new configuration to CCM without Applying configuration"?
Please let us know if you have any other questions or concerns.

-Jason
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Weird entries in audit log

Post by BanditBBS »

Jason, nope. And I am aware how the import works, have used it many time, not sure why all those files would have been in that folder to begin with. But there wasn't even any login to Nagios that day nor the previous few days.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
DoubleDoubleA
Posts: 199
Joined: Thu Feb 09, 2017 5:07 pm

Re: Weird entries in audit log

Post by DoubleDoubleA »

You are likely best served by putting in a ticket on this issue with the support team. Getting to the bottom of it will likely require a level of troubleshooting and investigation that the forum is not set up for.

Thanks,

Aaron
User avatar
tgriep
Madmin
Posts: 9190
Joined: Thu Oct 30, 2014 9:02 am

Re: Weird entries in audit log

Post by tgriep »

When Nagios XI is upgraded, the upgrade at certain times, upgrades all of the Wizards and the wizard upgrade, sets the commands to what is needed fro the wizard so what you are seeing is normal if XI was upgraded.

Was XI upgraded on that day at that time?
Be sure to check out our Knowledgebase for helpful articles and solutions!
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Weird entries in audit log

Post by BanditBBS »

No, there were no logins to XI that day, nothing was done, that's why it is baffling.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
DoubleDoubleA
Posts: 199
Joined: Thu Feb 09, 2017 5:07 pm

Re: Weird entries in audit log

Post by DoubleDoubleA »

Are you able to look at OS-level logins? The scripts that generate those log entries could have been run from the command line. Perhaps unlikely but if there aren't any interface logins, it is at least possible.
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Weird entries in audit log

Post by BanditBBS »

Only thing really run is dnf upgrade -y

We search longer back in the audit log and we see this happening in July, August, Sept and November..all on different dates that do not line up with the OS patches and no RFC.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
DoubleDoubleA
Posts: 199
Joined: Thu Feb 09, 2017 5:07 pm

Re: Weird entries in audit log

Post by DoubleDoubleA »

Is it an rpm install of XI?

And is your signature accurate, you're on 5.6?
User avatar
BanditBBS
Posts: 2474
Joined: Tue May 31, 2011 12:57 pm
Location: Scio, OH
Contact:

Re: Weird entries in audit log

Post by BanditBBS »

Oh wow, haven't updated signature in quite some time. It is RPM install as it was the offline installation.
2 of XI5.6.14 Prod/DR/DEV - Nagios LogServer 2 Nodes
See my projects on the Exchange at BanditBBS - Also check out my Nagios stuff on my personal page at Bandit's Home and at github
Post Reply