HP StorageWorks P9000 Command View Advanced Edition Suite Software 7.1.1 Administrator Guide (web) (TB581-96065, September 2011)

DescriptionCategories
Events indicating that a device, administrator, or end user succeeded
or failed in connection or authentication:
FC login
Device authentication (FC-SP authentication, iSCSI login authentica-
tion, SSL server/client authentication)
Administrator or end user authentication
Authentication
Events indicating that a device, administrator, or end user succeeded
or failed in gaining access to resources:
Access control for devices
Access control for the administrator or end users
AccessControl
Events indicating that attempts to access important data succeeded or
failed:
Access to important files on NAS or to contents when HTTP is sup-
ported
Access to audit log files
ContentAccess
Events indicating that the administrator succeeded or failed in performing
an allowed operation:
Reference or update of the configuration information
Update of account settings including addition or deletion of accounts
Security configuration
Reference or update of audit log settings
ConfigurationAccess
Events indicating that a performed maintenance operation succeeded
or failed:
Addition or deletion of hardware components
Addition or deletion of software components
Maintenance
Events indicating that an anomaly, such as a threshold being exceeded,
occurred:
A network traffic threshold was exceeded
A CPU load threshold was exceeded
Pre-notification that a limit is being reached or a wraparound oc-
curred for audit log data temporarily saved internally
AnomalyEvent
Events indicating that abnormal communication occurred:
SYN flood attacks to a regularly used port, or protocol violations
Access to an unused port (port scanning, etc.)
Different products generate different types of audit log data.
For details on the contents of the output audit log data, see Checking audit log data on page 264.
Information included in audit logs
In Device Manager and Tiered Storage Manager, the following categories of audit events are output
to audit logs:
StartStop
Administrator Guide (Web Version) 109