18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 19: Auditing and Reporting<br />

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

Table 34: Custom audit filter fields<br />

546<br />

Field Description<br />

facility Specify an event facility code (such as AUDIT_F_LOGIN, AUDIT_F_PROXY, etc.). For<br />

a complete list <strong>of</strong> the available facility codes, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the<br />

srole command and then enter the following command: acat -c | more<br />

type Specify an event type code (for example, type AUDIT_T_NETTRAFFIC). For a<br />

complete list <strong>of</strong> the available type codes, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the srole<br />

command and then enter the following command: acat -c | more<br />

category Specify an event category code (for example, AUDIT_C_POLICY_VIOLATION). For a<br />

complete list <strong>of</strong> the available category codes, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the<br />

srole command and then enter the following command: acat -c | more<br />

eventid Specify an event identifier code (for example, AUDIT_R_LICEXCEEDED). For a<br />

complete list <strong>of</strong> the available event identifiers, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the<br />

srole command and then enter the following command: acat -c | more<br />

pid Specify the process ID <strong>of</strong> the auditing process.<br />

pgid Specify the process group ID <strong>of</strong> the auditing process.<br />

ruser Specify the real user ID <strong>of</strong> the auditing process.<br />

euser Specify the effective user ID <strong>of</strong> the auditing process.<br />

username Specify a user name.<br />

src_ip Specify the source IP address using the dotted decimal IP version 4 notation, with<br />

optional mask bits separated by a slash (/).<br />

dst_ip Specify the destination IP address using the dotted decimal IP version 4 notation, with<br />

optional mask bits separated by a slash (/).<br />

src_port Specify the TCP or UDP source port.<br />

dst_port Specify the TCP or UDP destination port.<br />

src_burb Specify the source burb number.<br />

dst_burb Specify the destination burb number.<br />

service Specify the type <strong>of</strong> service (for example, Telnet, FTP, WebProxy, etc.).<br />

vpn_l_gw Specify a VPN local gateway using the standard dotted decimal IP version 4 notation<br />

with optional mask bits separated by a slash (/).<br />

vpn_r_gw Specify a VPN remote gateway using the dotted decimal IP version 4 notation with<br />

optional mask bits separated by a slash (/).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!