HP StorageWorks P9000 Command View Advanced Edition Suite Software 7.1.1 Administrator Guide (web) (TB581-96065, September 2011)
DescriptionCategories
Events indicating that a device, administrator, or end user succeeded
or failed in connection or authentication:
• FC login
• Device authentication (FC-SP authentication, iSCSI login authentica-
tion, SSL server/client authentication)
• Administrator or end user authentication
Authentication
Events indicating that a device, administrator, or end user succeeded
or failed in gaining access to resources:
• Access control for devices
• Access control for the administrator or end users
AccessControl
Events indicating that attempts to access important data succeeded or
failed:
• Access to important files on NAS or to contents when HTTP is sup-
ported
• Access to audit log files
ContentAccess
Events indicating that the administrator succeeded or failed in performing
an allowed operation:
• Reference or update of the configuration information
• Update of account settings including addition or deletion of accounts
• Security configuration
• Reference or update of audit log settings
ConfigurationAccess
Events indicating that a performed maintenance operation succeeded
or failed:
• Addition or deletion of hardware components
• Addition or deletion of software components
Maintenance
Events indicating that an anomaly, such as a threshold being exceeded,
occurred:
• A network traffic threshold was exceeded
• A CPU load threshold was exceeded
• Pre-notification that a limit is being reached or a wraparound oc-
curred for audit log data temporarily saved internally
AnomalyEvent
Events indicating that abnormal communication occurred:
• SYN flood attacks to a regularly used port, or protocol violations
• Access to an unused port (port scanning, etc.)
Different products generate different types of audit log data.
For details on the contents of the output audit log data, see “Checking audit log data” on page 264.
Information included in audit logs
In Device Manager and Tiered Storage Manager, the following categories of audit events are output
to audit logs:
• StartStop
Administrator Guide (Web Version) 109