Connectivity Guide

To disable audit logging, enter the no logging audit enable command.
View audit log
Display audit log entries in EXEC mode. By default, 24 entries are displayed, starting with the oldest event. Enter reverse to display
entries starting with the most recent events. You can change the number of entries displayed.
show logging audit [reverse] [number]
Clear audit log
Clear all events in the audit log in CONFIGURATION mode.
clear logging audit
Example
OS10(config)# logging audit enable
OS10(config)# exit
OS10# show logging audit 4
<14>1 2019-02-14T13:15:06.283337+00:00 OS10 audispd - - - Node.1-Unit.1:PRI [audit], Dell EMC
(OS10) node=OS10 type=USER_END msg=audit(1550150106.277:597): pid=7908 uid=0 auid=4294967295
ses=4294967295 msg='op=PAM:session_close acct="admin" exe="/bin/su" hostname=? addr=?
terminal=??? res=success'
<110>1 2019-02-14T13:15:16.331515+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'crypto security-profile mltestprofile' - success
<110>1 2019-02-14T13:15:21.794529+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:16:05.882555+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'exit' - success
OS10# show logging audit reverse 4
<110>1 2019-02-14T13:16:05.882555+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:15:21.794529+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'exit' - success
<110>1 2019-02-14T13:15:16.331515+00:00 OS10 .clish 7412 - - Node.1-Unit.1:PRI [audit], User
admin on console used cmd: 'crypto security-profile mltestprofile' - success
<14>1 2019-02-14T13:15:06.283337+00:00 OS10 audispd - - - Node.1-Unit.1:PRI [audit], Dell EMC
(OS10) node=OS10 type=USER_END msg=audit(1550150106.277:597): pid=7908 uid=0 auid=4294967295
ses=4294967295 msg='op=PAM:session_close acct="admin" exe="/bin/su" hostname=? addr=?
terminal=??? res=success'OS10# show logging audit reverse 10
Security commands
aaa accounting
Enables AAA accounting.
Syntax
aaa accounting commands all {console | default} {start-stop | stop-only | none}
[logging] [group tacacs+]
Parameters
commands all — Record all user-entered commands. This option is not supported for RADIUS accounting.
console — Record all user authentication and logins or all user-entered commands in OS10 sessions on
console connections.
default — Record all user authentication and logins or all user-entered commands in OS10 sessions on
remote connections; for example, Telnet and SSH.
start-stop — Send a start notice when a process begins, and a stop notice when the process ends.
stop-only — Send only a stop notice when a process ends.
800 Security