System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Monitor XR shell commands

Want to summarize with AI?

Log in

Explains how monitoring XR shell captures, associates, and protects audit records of shell commands for enhanced security and compliance.


Monitor XR shell commands is an IOS XR security capability that

  • audits run and bash sessions on the active Route Processor (RP) but excludes shell built-in commands

  • associates each command with the original authenticated user, and

  • sends execution events to a logging mechanism called the shell-logger.

The Shell-Logger uses Tetragon to provide command accountability for monitored IOS XR run and bash sessions on the active Route Processor (RP). It creates protected audit records that associate shell activity with authenticated IOS XR users, supporting security monitoring, compliance, and troubleshooting. Run and bash sessions on the standby RP or other nodes are not monitored.

Tetragon runtime observability

Tetragon, an extended Berkeley Packet Filter (eBPF)-based runtime observability engine, uses eBPF programs to track kernel-level process execution events. Each tracked process execution—including shell commands, script-based commands, and commands executed in nested shells—generates an event. Each event records the timestamp, username, executed command, and whether the command originated from an IOS XR run or bash session.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

Monitor XR shell commands

Release 26.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100])

You can now trace run and bash commands to specific users and identify potential system compromises. By implementing shell-level user activity tracking, the router records each action, the user who performed it, and its timestamp. You can use this data to monitor user behavior, detect potentially malicious activity, and respond rapidly to security incidents.

This feature introduces these changes:

CLI:


Export shell history before an install operation

Ensure that shell audit history is preserved by exporting it from volatile storage before executing installation or upgrade operations.

Files under /var/log/xr-shell-logger/ do not persist across package installations or image upgrades. Exporting history allows you to retain records for compliance and troubleshooting.

Before you begin

  • Identify the route-processor location containing the shell history.

  • Determine a persistent destination for backup, such as harddisk:

Follow these steps to export shell history before an install operation:

Procedure

  1. Display the history for the required route processor.

    Example:

    Router#show shell history location 0/RP0/CPU0
    Mon Jul 13 12:27:24.451 UTC
    
    Time                          User       Origin         Command
    ----------------------------  ---------- ----------  --------------------------------
    Aug  3 2026 17:41:23.541 UTC  user       run        /bin/sh -c -- "cat /proc/57392/cmdline"
    Aug  3 2026 17:41:23.546 UTC  user       run        /usr/bin/cat /proc/57392/cmdline
    Aug  3 2026 17:41:23.548 UTC  user       run        /bin/sh -c -- "ps -p 57392 -o ppid="
    Aug  3 2026 17:41:23.551 UTC  user       run        /usr/bin/ps -p 57392 -o ppid=
    Aug  3 2026 17:41:23.579 UTC  user       run        /bin/sh -c -- "cat /proc/57365/cmdline"
    Aug  3 2026 17:41:23.583 UTC  user       run        /usr/bin/cat /proc/57365/cmdline
    Aug  3 2026 17:41:23.585 UTC  user       run        /bin/sh -c -- "ps -p 57365 -o ppid="
    Aug  3 2026 17:12:35.222 UTC  user       bash       /bin/hostname
    Aug  3 2026 17:12:35.223 UTC  user       bash       /bin/less -V
    Aug  3 2026 17:12:35.225 UTC  user       bash       /bin/tty
    Aug  3 2026 17:12:40.733 UTC  user       bash       /bin/ls -lrt
    Aug  3 2026 17:12:43.637 UTC  user       bash       /bin/uname -a
    Aug  3 2026 17:12:46.309 UTC  user       bash       /bin/whoami
    This output displays a table of commands run, including timestamp, user, origin, and command details.
  2. Export the history to persistent storage.

    Example:

    RP/0/RP0/CPU0:SFDR1#show shell history location 0/RP0/CPU0 | file harddisk:
    This saves the shell history to a location that is not cleared during install operations. You can also collect diagnostic data for the shell-logger process and save it to a specific storage location by using the show tech-support shell-logger file command. By adding file , you direct the output to a file instead of displaying it on the console.

The shell history is successfully exported to persistent storage and preserved prior to the install operation.

What to do next

Proceed with the package installation or image upgrade after exporting shell history.