SSH Reference Manual
"<1> AUDITCOLL stopped" 
•  CAUSE: STNCOM command AUDITCOLL OFF was used. This event is written to the specified 
AUDITCOLL collector, not to the standard $0 EMS event collector. 
•  EFFECT: Events are no longer written to the audit collector. Normal EMS event processing to $0 continues. 
•  RECOVERY: None; informational only. 
zstn-evt-auditcoll-sslmiscerr value is 1022 
"<1> AUDITCOLL sslmiscerr <2> <3> <4> <5>" 
<2>, <3>, <4> zero. Used only for SecurTN where this event has an alternate meaning. 
<5> text from AUDITMSG. 
•  CAUSE: Generated when STNCOM command AUDITMSG is used. This event is written to the specified 
AUDITCOLL collector, not to the standard $0 EMS event collector. 
•  EFFECT: None. 
•  RECOVERY: None; informational only. 
zstn-evt-auditcoll-service   value is 1023 
"<1> AUDITCOLL <2> <3> <4> service <5> Outcome <6>" 
<2> full name of the window (\node.$stn.#window). 
<3> remote IP address 
<4> remote IP port 
<5> window name only (#win) 
<6> text "Granted" for a dedicated window, and "Granted" or "Denied" for a service. 
•  CAUSE: Generated on a session connection attempt to a service or dedicated window. Outcome is GRANTED 
or DENIED for a service, GRANTED for a dedicated window. This event is written to the specified 
AUDITCOLL collector, not to the standard $0 EMS event collector. 
•  EFFECT: None. 
•  RECOVERY: None; informational only. 
zstn-evt-auditcoll-connect value is 1024 
"<1> AUDITCOLL connect <2> <3> <4> <5> Client Info <6>" 
<2> full name of the window (\node.#stn.#window)  
<3> remote IP address 
<4> remote IP port 
<5> text "PLAIN" for unencrypted sessions, or "SECURE". 
<6> encryption method. 
•  CAUSE: Generated when a new session is accepted from a remote workstation. The session can be either 
SECURE or PLAIN. This event is written to the specified AUDITCOLL collector, not to the standard $0 EMS 
event collector. 
HP NonStop SSH Reference Manual  STN Reference • 287 










