Format of audit messages

Prev Next

Audit records are stored locally and sent remotely at the same time.

The following is the general format of all syslog messages (unless otherwise specified):

TimestampHostnameprocess name[pid]: [subsystem.priority]: Message content

For example, a locally logged message looks like this:

Oct 25 23:32:32 cms9500-123 mgmtd[12393]: [mgmtd.NOTICE]: mgmtd starting at 2023/10/25 23:32:32.675May  7 18:27:40 NX-7500-160 pm[5916]: [pm.NOTICE]: AUDIT: System initialization completed

For example, a remotely logged message (excluding any remote post-processing) looks like this:

May  7 18:27:40 NX-7500-160 pm[5916]: [pm.NOTICE]: AUDIT: System initialization completed