Management and Configuration Guide (Includes ACM xl) 2005-12

9-6 ProCurve Secure Access 700wl Series Management and Configuration Guide
Logs
Viewing the Session Logs
The 700wl Series system log files provide informational messages, warnings and so on about the
operation of the 700wl Series system. Session logging goes further to provide information about every
completed session. These logs are optional. If enabled, log entries are sent to an remote Syslog server
that you specify when you enable session logging. For information on enabling session logging, see
“Configuring Session Logging” on page 9-4.
You cannot view the session log files from the Administrative Interface. You must view them on your
Syslog server.
You can view session status for an individual client under the Session Status tab in the Status module of
the Administrative Interface. See “Viewing Session Status” on page 3-10 for more information.
The Session Log Entry Format
The session log entries consists of a single line for each session, for example:
logmsg: pri 36, flags 0, from vm18.testbed.com, msg Nov 13 01:43:50
90466740 129 00:30:65:41:da:56 udp 42.230.129.94:5353 224.0.0.251:5353
10.10.10.18:5353 224.0.0.251:5353 474 0 test
The information in the first line of the example (the underlined fields through the date and time) is
added by the Syslog server. The information from the 700wl Series system starts with the second line of
the example (90466740, which is the start time of the session). The format of the data sent by the 700wl
Series system is:
Logging Off:
client Mac SESSION: Logging off [user name], with mac [client mac], [ip] from [am name]
[am mac], Name [Am IP], slot/port [slot]/[port]
Logon denied:
SESSION: - logon denied for mac: [client mac], sat: [AM mac], Name [AM IP], slot/port
[slot]/[port], [user name]
Successful Logon:
SESSION: Successful login mac: [client mac], sat: [AM mac], Name [AM IP], slot/port
[slot]/[port], {ip] [user name]
Client Session:
SESSION: CLIENT [start time - seconds since 1/1/2000 GMT] [end time - start time]
[client mac] [AM IP] [slot]/[port] [internal vlan id]/[external vlan id] [protocol]
[client source addr]:[client source port] [client dist addr]:[client dist port] [actual
source addr]:[actual source port] [actual distination addr]:[actual dist port] [total
transmit octets] [total receive octets] [user]"
Associate:
SESSION: ASSOC [current time] [mac address] [IP addr] {slot]/[port] [internal