Auditing and logging

Information

ArubaOS-Switch provides both locally stored event and security logs, as well as using the syslog protocol to forward events to a remote server for auditing purposes. Logged events can be filtered by severity level, originating system modules, or using regular expressions to match against message text.

Solution

The syslog client is capable of connecting to a server using UDP (default) or TCP protocols. Use the following command to configure the switch to forward all events with a severity of warning or higher to a syslog server located at 10.100.1.250 using the mgmt VRF:

switch(config)# logging 10.100.1.250 vrf mgmt severity warning

See Also

https://support.hpe.com/hpesc/public/docDisplay?docId=a00053695en_us

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: ArubaOS

Control ID: d46c393060cb74555f54d881747312e2c61ff99545d57608af49cbbf9dd6819f