Audit Logging

With audit logging, configuration changes to the system get logged in separate log files for auditing. The Cisco Audit Event Service, which displays under Control Center - Network Services in the serviceability GUI, monitors and logs any configuration changes to the system that are made by a user or as a result of the user action.

You access the Audit Log Configuration window in the serviceability GUI to configure the settings for the audit logs.

Audit logging contains the following parts:


Tip


Be aware that audit event logging is centralized and enabled by default. An alarm monitor called Syslog Audit writes the logs. By default, the logs are configured to rotate. If the AuditLogAlarmMonitor cannot write an audit event, the AuditLogAlarmMonitor logs this failure as a critical error in the syslog file. The Alert Manager reports this error as part of a SeverityMatchFound alert. The actual operation continues even if the event logging fails. All audit logs get collected, viewed, and deleted from Trace and Log Central in the Cisco Unified Real-Time Monitoring Tool.


Cisco Unified Serviceability Events Logging

Cisco Unified Serviceability logs the following events:

Cisco Unified Real-Time Monitoring Tool Events Logging

Cisco Unified Real-Time Monitoring Tool logs the following events with an audit event alarm:

Cisco Cisco Unified Communications Manager CDR Analysis and Reporting Events Logging

Cisco Cisco Unified Communications Manager CDR Analysis and Reporting (CAR) creates audit logs for these events:

Cisco Cisco Unified Communications Manager Administration Events Logging

The following events get logged for various components of Cisco Cisco Unified Communications Manager Administration:

Cisco Cisco Unified Communications Manager Administration Events Logging

The following events get logged for various components of Cisco Cisco Unified Communications Manager Administration:

Cisco Cisco Unified Communications Manager User Options Logging

User logging (user login and user logout) events are logged for Cisco Cisco Unified Communications Manager User Options.

Command-Line Interface Events Logging

All commands issued via the command-line interface are logged (for both Cisco Cisco Unified Communications Manager and Cisco Unity Connection).

Cisco Unity Connection Administration Events Logging

Cisco Unity Connection Administration logs the following events:

Cisco Personal Communications Assistant (Cisco PCA)

The Cisco Personal Communications Assistant client logs the following events:

Cisco Unity Connection Serviceability Events Logging

Cisco Unity Connection Serviceability logs the following events:

Cisco Unity Connection Clients that Use the Representational State Transfer APIs Events Logging

Cisco Unity Connection clients that use the Representational State Transfer (REST) APIs log the following events:

Cisco Unified IM and Presence Serviceability Events Logging

Cisco Unified IM and Presence Serviceability logs the following events:
  • Activation, deactivation, start, or stop of a service

  • Changes in trace configurations and alarm configurations

  • Changes in SNMP configurations

  • Review of any report in the Serviceability Reports Archive (this log gets viewed on the reporter node)

Cisco Unified IM and Presence Real-Time Monitoring Tool Events Logging

Cisco Unified IM and Presence Real-Time Monitoring Tool logs the following events with an audit event alarm:
  • Alert configuration

  • Alert suspension

  • E-mail configuration

  • Set node alert status

  • Alert addition

  • Add alert action

  • Clear alert

  • Enable alert

  • Remove alert action

  • Remove alert

Cisco Cisco Unified Communications Manager IM and Presence Administration Events Logging

The following events get logged for various components of Cisco Cisco Unified Communications Manager IM and Presence Administration:
  • Administrator logging (logins and logouts on IM and Presence interfaces such as Administration, OS Administration, Disaster Recovery System, and Reporting)

  • User role membership updates (user added, user deleted, user role updated)

  • Role updates (new roles added, deleted, or updated)

  • Device updates (phones and gateways)

  • Server configuration updates (changes to alarm or trace configurations, service parameters, enterprise parameters, IP addresses, hostnames, Ethernet settings, and IM and Presence server additions or deletions)

IM and Presence Application Events Logging

The following events get logged by the various components of the IM and Presence Application:
  • End user logging on IM clients (user logins, user logouts, and failed login attempts)

  • User entry to and exit from IM Chat Rooms

  • Creation and destruction of IM Chat Rooms

Command Line Interface Events Logging

All commands issued through the command line interface are logged.