Brocade Fabric OS Message Reference - Supporting Fabric OS v7.0.1 (53-1002448-01, March 2012)

2 Fabric OS Message Reference
53-1002448-01
Overview of system messages
1
For information on displaying and clearing the RASLog messages, refer to “Displaying and clearing
system message logs” on page 15.
Audit log messages
Event auditing is designed to support post-event audits and problem determination based on
high-frequency events of certain types such as security violations, zoning configuration changes,
firmware downloads, and certain types of fabric events. Audit messages flagged as AUDIT are not
saved in the switch error logs. The switch can be configured to stream Audit messages to the switch
console and to forward the messages to specified syslog servers. The Audit log messages are not
forwarded to an SNMP management station. There is no limit to the number of audit events.
The following is an example of an Audit message.
0 AUDIT, 2001/01/14-06:07:33 (UTC), [SULB-1003], INFO, FIRMWARE,
admin/admin/10.70.4.102/telnet/CLI ad_0/switch, , Firmwarecommit has started.
For any given event, Audit messages capture the following information:
User Name - The name of the user who triggered the action.
User Role - The access level of the user, such as root or admin.
Event Name - The name of the event that occurred.
Event Information - Information about the event.
The seven event classes described in Table 1 can be audited.
Fabric OS v7.0.1 generates component-specific Audit messages. Refer to Audit Log Messages”.
TABLE 1 Event classes
Operand Event class Description
1 Zone You can audit zone event configuration changes, but not the actual
values that were changed. For example, you may receive a message
that states “Zone configuration has changed,” but the message
does not display the actual values that were changed.
2 Security You can audit any user-initiated security event for all management
interfaces. For events that have an impact on the entire fabric, an
audit is only generated for the switch from which the event was
initiated.
3 Configuration You can audit configuration downloads of existing SNMP
configuration parameters. Configuration uploads are not audited.
4 Firmware You can audit configuration downloads of existing SNMP
configuration parameters. Configuration uploads are not audited.
5 Fabric You can audit Administration Domain-related changes.
6 FW You can audit Fabric Watch (FW)-related changes.
7 LS You can audit Virtual Fabric (Logical Switch)-related changes.