Multiexcerpt | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||
OverviewThe SBC Core supports multiple event log types. The two most applicable SBC security-related event log types are the Security and Audit logs.
Sonus recommends setting the Filter Level for those two event types to Info-level logging for maximum security visibility.
Downloading/Deleting Event Log Files
Viewing/Filtering Audit Log FilesThe SBC is capable of collecting two types of Audit logs:
To view and/or filter Platform and Event audit logs, login to the EMA and navigate to Troubleshooting > Troubleshooting Tools > Search Audit Logs. The Audit Logs window displays. |
The Audit Logs are system audit data. These files contain a record of all management interactions that modify the state of the system, and includes all the changes made via EMA, EMS and CLI interfaces. These files use .AUD extensions. The logs are generated and stored at Log Management.
From the EMA main screen, navigate to Troubleshooting > Troubleshooting Tools >Search Audit Logs. The Search Audit Log window is displayed.
Caption | ||||
---|---|---|---|---|
| ||||
Two types of logs are displayed in the table:
To view the logs for any particular type, select the corresponding type.
Caption | ||||
---|---|---|---|---|
| ||||
You can filter the logs to view only the required logs.
...
Caption | ||||
---|---|---|---|---|
| ||||
Note | ||
---|---|---|
| ||
The Event Audit Logs and the Platform Audit Logs are stored by the SBC. For each type of log, the SBC stores a maximum of 512 records. The logs are available for download or deletion. For further details on downloading, viewing or deleting the logs, refer to Log Management. |