show log audit

Prev Next

Displays the active audit log file, a list of all audit log files, an archived audit log file, or selected entries in the active audit log. You can also display audit log entries continuously as they are added to the active log.

Syntax

show log audit [files [log_id] | continuous | matching regular_expression | not matching regular_expression]

Parameters

files [log_id]

Lists the name and ID number of each log file, and the date and time of its first and last entries. To view the entries in an archived log, specify their log ID (to view the active log, enter show log).

continuous

Displays each log entry as it is added to the active log.

matching regular_expression

Displays the log entries in the active log that match the specified regular expression. All special characters supported by the UNIX grep utility can be used here, such as “*” to indicate any string of text and “?” to indicate any single character.

not matchingregular_expression

Displays the log entries in the active log that do not match the specified regular expression. All special characters supported by the UNIX grep utility can be used here, such as “*” to indicate any string of text and “?” to indicate any single character.

Example

The following example displays the audit log entries for the standard log format.

Jan 24 00:00:00 Belize mgmtd[6768]: [mgmtd.NOTICE]: AUDIT: Action ID 1256: requested by: user fenet (FENet Process) (UNCONFIRMED) via Mdreq (session ID 40557)
Jan 24 00:00:00 Belize mgmtd[6768]: [mgmtd.NOTICE]: AUDIT: Action ID 1256: descr: Run the aggregator
Jan 24 00:00:00 Belize mgmtd[6768]: [mgmtd.NOTICE]: AUDIT: Action ID 1256: param: aggregator name: "rt-stats-aggr"
Jan 24 00:00:00 Belize mgmtd[6768]: [mgmtd.NOTICE]: AUDIT: Action ID 1256: param: action: "bundle"
Jan 24 00:00:00 Belize mgmtd[6768]: [mgmtd.NOTICE]: AUDIT: Action ID 1256: param: archive file: "/data/fenet/stats-content/.upload/rt-stats-aggr.tbz2"
Jan 24 00:00:00 Belize cli[8101]: [cli.NOTICE]: AUDIT: user #0/0: Executing command: en
Jan 24 00:00:00 Belize cli[8101]: [cli.NOTICE]: AUDIT: user #0/0: Executing command: show version
Jan 24 00:00:00 Belize cli[8101]: [cli.NOTICE]: AUDIT: user #0/0: Executing command: show clock
Jan 24 00:00:00 Belize cli[8101]: [cli.NOTICE]: AUDIT: user #0/0: Executing command: show guest-images
...

Supported appliances

This command is supported on the following appliance running the specified release or later:

  • Endpoint Security (HX): Release 2.5