Configures audit logging on Cisco NCS 1014 by enabling audit rule groups, verifying their status, and optionally forwarding audit logs to a remote syslog server.
Configure and monitor audit logs for specific system events by enabling the relevant audit rule groups.
Enable audit rule groups to monitor specific files, directories, or system events. Optional syslog forwarding sends audit logs to a configured remote syslog server for centralized analysis.
Procedure
| 1. | Enter the linux security audit monitor <group-keyword> command to enable a group of audit rules. Example:
|
|
| 2. | Enter the show linux security audit monitor status command to verify the general status of all active audit rule groups. Example:
|
|
| 3. | Optional: Enter the linux security audit logging syslog command to enable forwarding of audit logs. Example:
|
|
| 4. | Optional: Enter the logging remote-server-ip vrf vrf-name command to configure the remote syslog server. Example:
|
|
| 5. | Optional: Enter the show linux security audit logging syslog command to verify whether audit log forwarding is enabled and to view the configured remote syslog server. Example:
|
Audit logging monitors the enabled rule groups and forwards audit logs when syslog forwarding and remote server configuration are enabled.