Audit Log questions
Posted: Mon Apr 17, 2017 1:22 pm
Is there a place where I can lookup the ID= information found in /usr/local/nagiosxi/var/components/auditlog.log
for example...
what is ID 1100 ?
I will look in code, or docs, whatever. I just need to know what it means.
My company is moving closer to becoming DFARS complaint and I have been able so far to stay ahead of the requests. Audit logging is an important one.
I would like to ask for something like verbose mode for the audit log if possible - to have more specific information provided. The short-hand data in the file now is barely adequate. I am not completely sure what to ask for. But I need to see more information than I see today.
Above is one example. I have no idea what that user clicked on.
Another example here:
This line is from the audit log:
What did the user click to make this happen? The people getting Audit data in the future will be asking for better information.
Is there some way to get better or more clear data in the audit log.
Thanks
Steve B
for example...
Code: Select all
User submitted a command to the subsystem (ID=1100)I will look in code, or docs, whatever. I just need to know what it means.
My company is moving closer to becoming DFARS complaint and I have been able so far to stay ahead of the requests. Audit logging is an important one.
I would like to ask for something like verbose mode for the audit log if possible - to have more specific information provided. The short-hand data in the file now is barely adequate. I am not completely sure what to ask for. But I need to see more information than I see today.
Above is one example. I have no idea what that user clicked on.
Another example here:
This line is from the audit log:
Code: Select all
2017-04-17 05:08:02 - Nagios XI [32] system:localhost - cmdsubsys: User [username] started Nagios CoreIs there some way to get better or more clear data in the audit log.
Thanks
Steve B