cancel
Showing results for 
Search instead for 
Did you mean: 

ERS4900/5900 config audit logging

ERS4900/5900 config audit logging

EF
Contributor II

Hi folks!!

 

I need enabled audit logging in ERS4900/5900 series, but I not sure if the only option available is enabling enhanced secure mode on switches which is no option due to all changes that introduces in users and password management. Any idea?

 

Regards

EF

 

 

1 ACCEPTED SOLUTION

Todd_Hancock
New Contributor III

Hi EF,
It is automatic.
From the Security manual:
A special area of flash memory reserved for CLI audit stores the command history. Access to this
area is read-only. When you enable remote logging, the audit message is also forwarded to a
remote syslog server, no matter the logging level.

I have always seen the audit log entries on our syslog server.

View solution in original post

3 REPLIES 3

Todd_Hancock
New Contributor III

Hi EF,
It is automatic.
From the Security manual:
A special area of flash memory reserved for CLI audit stores the command history. Access to this
area is read-only. When you enable remote logging, the audit message is also forwarded to a
remote syslog server, no matter the logging level.

I have always seen the audit log entries on our syslog server.

EF
Contributor II

Thanks Todd, I saw it but, how can i send it to syslog server?

 

Regards,

 

EF

 

 

Todd_Hancock
New Contributor III

Audit logging is enabled by default - command is : audit log save.
View the logs with command : show audit log.

GTM-P2G8KFN