System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Command accounting methods

Want to summarize with AI?

Log in

Outlines command accounting methods, providing configuration procedures for recording and auditing user command activities within network devices.


A command accounting method is a logging method that

  • records commands executed by users as syslog messages

  • allows only users with AAA write permissions to enable or disable accounting, and

  • does not support commands executed via NETCONF, XML, or gRPC.

Additional reference information

Command accounting enables logging of all commands executed by any user as syslog messages, provided the accounting method is set to local. Only users with AAA write permissions can manage the feature. Commands recorded via command accounting can be viewed using the show logging command. Command accounting functions as an additional accounting method and remains active alongside other configured accounting methods; it is not a failover method.


Configure command accounting

Enable command accounting to log the commands that users execute on the router.

Command accounting can be configured alone or in combination with other accounting methods to ensure commands are logged as syslog messages.

Before you begin

You must have AAA write permissions to enable or disable command accounting.

Procedure

Determine whether you want to configure command accounting alone or alongside other accounting methods.

To configure command accounting alone, enter the following command in configuration mode.

Example:

Router(config)# aaa accounting commands default start-stop local none
Router(config)# commit

Example:

Router(config)# aaa accounting commands default start-stop group tacacs+ local none
Router(config)# commit

To configure command accounting together with another accounting method (such as TACACS+):

Example:

Router(config)# aaa accounting commands default start-stop group tacacs+ local none
Router(config)# commit

Command accounting is enabled, and user command execution can now be reviewed from the syslog output.