HP P9000 Command View Advanced Edition Suite Software 7.4.0-00 Administrator Guide (web) (TB581-96325, December 2012)

Table Of Contents
DescriptionCategories
Events indicating that abnormal communication occurred:
SYN flood attacks to a regularly used port, or protocol violations
Access to an unused port (port scanning, etc.)
Different products generate different types of audit log data.
For details on the contents of the output audit log data, see Checking audit log data on page 297.
Information included in audit logs
In Device Manager and Tiered Storage Manager, the following categories of audit events are output
to audit logs:
StartStop
Authentication
ConfigurationAccess
AccessControl
ExternalService
Each audit event is assigned a severity level. You can filter audit log data to be output according to
the severity levels of events.
Table 36 to Table 40 describe the audit log data that can be generated by Device Manager and
Tiered Storage Manager. For details on the audit log data generated by other P9000 Command
View AE Suite products, see the manuals for the relevant products.
Table 36 Audit events that are output to audit logs (when the category is StartStop)
Message IDSeverityAudit eventType description
KAPM00090-I6Successful SSO server start
Start and stop of
software
KAPM00091-E3Failed SSO server start
KAPM00092-I6SSO server stop
Table 37 Audit events that are output to audit logs (when the category is Authentication)
Message IDSeverityAudit eventType description
KAPM01124-I6Successful login
Administrator or
end user authentica-
tion
KAPM02450-I6
Successful login (to the external authentication
server)
KAPM02291-W4Failed login (wrong user ID or password)
KAPM02291-W4Failed login (logged in as a locked user)
KAPM02291-W4Failed login (logged in as a non-existing user)
KAPM01095-E4Failed login (no permission)
KAPM01125-E4Failed login (authentication failure)
Administrator Guide (Web Version) 121