Enables or disables the logging of system changes to a AAA accounting server.
When change accounting is enabled, system actions are logged when the action is started, not when the action has completed. When more than one accounting server is specified, the configuration logging process contacts each accounting server in the order listed in the configuration until a server accepts the accounting data. If no accounting server accepts the accounting data, the log entry is discarded.
Note
While change accounting includes configuration changes and system actions that are visible with audit logging, change accounting is an independent process. Change accounting is not affected by the
configuration audit max-changesconfiguration.
Syntax
[no] aaa accounting changes default stop-only <method>
Parameters
no
Use the no form of this command to remove the configuration options currently set.
method
Specify the accounting protocol used. The following accounting protocols are available: tacacs+: Terminal Access Controller Access Control System Plus (TACACS+) access control protocol
Example
The following example enables system change logging on a TACACS+ server:
hostname (config) # aaa accounting changes default stop-only tacacs+
The following example disables system change logging on a TACACS+ server:.
hostname (config) # no aaa accounting changes default stop-only tacacs+
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Before release 6.4
Central Management System: Before release 6.4
Email Security — Server: Before release 6.4
File Protect: Before release 6.4
Endpoint Security (HX): Release 2.5
Network Security: Before release 6.4
Intelligent Virtual Execution - Server: 7.9