Administrator and FindMe user events
Administrator session related events are:
n
Admin Session Start
n
Admin Session Finish
n
Admin Session Login Failure
FindMe user session related events are:
n
User Session Start
n
User Session Finish
n
User Session Login Failure
For both administrator and FindMe user related events, the
Detail
field includes:
n
the name of the administrator or FindMe user to whom the session relates, and their IP address
n
the date and time that the login was attempted, started, or ended
Message details field
For all messages logged from the
tvcs
process, the
message_details
field, which contains the body of
the message, consists of a number of human-readable
name=value
pairs, separated by a space.
The first name element within the
message_details
field is always
Event
and the last name element is
always
Level
.
The table below shows all the possible name elements within the
message_details
field, in the order that
they would normally appear, along with a description of each.
Note: in addition to the events described below, a
syslog.info
event containing the string
MARK
is logged
after each hour of inactivity to provide confirmation that logging is still active.
Name
Description
Event
The event which caused the log message to be generated. See
Events and levels
for a list of all
events that are logged by the VCS, and the level at which they are logged.
User
The username that was entered when a login attempt was made.
ipaddr
The source IP address of the user who has logged in.
Protocol
Specifies which protocol was used for the communication. Valid values are:
n
TCP
n
UDP
n
TLS
Reason
Textual string containing any reason information associated with the event.
Cisco VCS Administrator Guide (X8.1.1)
Page 358 of 507
Reference material
About Event Log levels