HP XP7 Audit Log User and Reference Guide (H6F56-96001)

Table Of Contents
Table 6 Items in the Syslog File (RFC5424-compliant) (continued)
DescriptionItemNo.
The process name (-).Process name
The message ID (-).Message ID
The structured data (-).Structured data
The unified specification identifier (CELFSS).Unified specification
identification
The revision number of the unified specification document (1.1).
The serial number of the syslog header information.Message identification
The category name of the event.Type of audit event
Authentication of RMI, FC-SP, or Remote Web Console.
ConfigurationAccess indicates setting from Remote Web Console, SVP or host.
Maintenance indicates SVP operations.
AnomalyEvent indicates reached the maximum of the Audit Log, etc.
ExternalService indicates remote maintenance operations through SVP.
Result of audit event
Success: Normal end. The operation has ended normally.
Failed: Error (xxxx-yyyy). The operation has ended abnormally.
Failed: Warning (xxxx-yyyy). The operation has partly ended abnormally or was
canceled during the operation.
"xxxx-yyyyy" indicates error codes and it is output only for Remote Web Console
operations.
The user name in the format of "uid=user name".Account identification
<system> is output when the category name is AnomalyEvent.
<DKCMaintenance> is output for SVP operations.
<Host> is output for commands from host.
The ID (R800) to identify the model name of the product and the serial number divided
by a colon.
Hardware identification
The location identification name set by the user in the Syslog tab of Edit Audit Log
Settings window.
Related information
Identification of the host sending the request.Detailed information
This information is output when a command is received from the host unless it is FC-SP
authentication.
Collective operation identifier. This is a serial number that identifies those multiple
lines displayed by one operation are the same operation.
Outputs only if the log type information is "BasicLog" and the category name is other
than "AnomalyEvent".
Log type information:
BasicLog: basic information
DetailLog: detailed information
No output when the category name is "AnomalyEvent".
24 Introduction