18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

Filter Type Description<br />

showaudit_authfailur<br />

e<br />

18-16 Monitoring, Auditing, and Reporting<br />

Displays audit events generated by each failed authentication attempt for both users or<br />

administrators.<br />

showaudit_netprobe Displays audit events generated by netprobe attempts.<br />

showaudit_syslog Displays audit events generated by syslog.<br />

showaudit_te Displays audit events generated by the Type Enforcement policy engine.<br />

showaudit_vpn Displays audit events generated by VPN.<br />

showaudit_conf Displays audit events generated by configuration changes (for example, database<br />

modifications).<br />

showaudit_not_conf Displays all audit events other than configuration changes.<br />

Creating custom audit filters<br />

The Custom option in the Filter By field allows you to define a custom<br />

filter to view more specialized audit information. The basic structure<br />

includes specifying the type (AUDIT_T_TYPE) or facility<br />

(AUDIT_F_FACILITY) for which you want to search, followed by<br />

additional fields to further specify the audit results. The fields are<br />

separated by Boolean operators (and, or, not) and grouped by<br />

parenthesis. The following examples demonstrate the basic structure<br />

used to create custom audit filters.<br />

Note: Table 18-2 provides a list <strong>of</strong> the available fields (for example, facility, type, service,<br />

user, etc.) that you can use to filter your audit search.<br />

Example 1: Filtering for login records<br />

The following example shows the format used to display all system<br />

login records (successful and unsuccessful):<br />

facility AUDIT_F_LOGIN<br />

If you want to view login records for a specific user, you would<br />

include a username, as follows:<br />

facility AUDIT_F_LOGIN and username Josephine

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!