Configuring Audit Events and Logging
The Session Smart Router can be configured to maintain a history of several different class of events in the event log, which can subsequently be used to support compliance audits, forensics on network issues related to configuration (misapplied or otherwise), and traceability. This document covers:
- Types of events available on the router
- Enabling the Audit events
Event Types
The events generated by the router are classified into the following categories:
Traffic Events
Traffic events are generated as sessions are created on the router. These include details such as the protocol, source address, source port, destination address and destination port. In addition, the success or failure status along with a reason code for failure cases are included in the event.
Administration Events
Various administration actions performed by a user such as SSH login generate this category of events. The events contain the details about the user action, whether or not the action was permitted, and the reason for any failures.
System Events
Various system level events such as service and process restarts are generated by this event category. The details include information about the user and details about the underlying action.
Alarm Events
All the SSR alarms generate an add event when the alarm is raised and a clear event when the alarm is cleared. The alarm events can be used to view the history of the events associated with the alarms. The alarm events are implicit events and cannot be disabled via configuration. See Alarms and Events for more details.