5.1

Table Of Contents
About the Syslog Format
Is this the same for SPOCK?
The system event message logged in the syslog has the following structure.
syslog header (timestamp + hostname + sysmgr/)
Timestamp (from the service)
Name/value pairs
Name and value separated by delimiter '::' (double colons)
Each name/value pair separated by delimiter ';;' (double semi-colons)
The fields and types of the system event contain the following information.
Event ID :: 32 bit unsigned integer
Timestamp :: 32 bit unsigned integer
Application Name :: string
Application Submodule :: string
Application Profile :: string
Event Code :: integer (possible values: 10007 10016 10043 20019)
Severity :: string (possible values: INFORMATION LOW MEDIUM HIGH CRITICAL)
Message ::
View the Audit Log
The Audit Logs tab provides a view into the actions performed by all vShield Manager users. The vShield
Manager retains audit log data for one year, after which time the data is discarded.
Procedure
1 Click Settings & Reports from the vShield Manager inventory panel.
2 Click the Audit Logs tab.
3 To view details of an audit log, click the text in the Operation column. When details are available for an
audit log, the text in the Operation column for that log is clickable.
4 In the Audit Log Change Details, select Changed Rows to display only properties whose values have
changed after the operation was performed.
Chapter 7 System Events and Audit Logs
VMware, Inc. 45