<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.4 CLI logging in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-4-cli-logging/m-p/2208277#M112381</link>
    <description>&lt;P&gt;I need to be able to see login and logoff of the admin to the ACS 5.4 CLI.&amp;nbsp; I would like remote syslog message anytime someone uses ssh to the ACS server CLI.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have have remote logging enabled and have tried both 6-inform and 7-debug loglevels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging 192.x.x.x&lt;/P&gt;&lt;P&gt;logging loglevel 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only message I see on my syslog server that suggests a login of the "admin" user is the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'comic sans ms', sans-serif;"&gt;Jun 13 21:30:54 acsservername debugd[13478]: [14209]: utils: cars_shellcfg.c[118] [admin]: Invoked carsGetConsoleConfig&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I see no message that the admin user logged off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried enabling "debug all" and I can see the logged in users via "show users" but I need some sort of log message so I can track and audit the log in attempts.&amp;nbsp; It would also be nice to&amp;nbsp; see password failure attempts which I don't see either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&amp;nbsp; Can the CLI of ACS 5.4 be configured to log this information?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:32:32 GMT</pubDate>
    <dc:creator>webstert</dc:creator>
    <dc:date>2019-03-11T03:32:32Z</dc:date>
    <item>
      <title>ACS 5.4 CLI logging</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-cli-logging/m-p/2208277#M112381</link>
      <description>&lt;P&gt;I need to be able to see login and logoff of the admin to the ACS 5.4 CLI.&amp;nbsp; I would like remote syslog message anytime someone uses ssh to the ACS server CLI.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have have remote logging enabled and have tried both 6-inform and 7-debug loglevels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging 192.x.x.x&lt;/P&gt;&lt;P&gt;logging loglevel 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only message I see on my syslog server that suggests a login of the "admin" user is the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'comic sans ms', sans-serif;"&gt;Jun 13 21:30:54 acsservername debugd[13478]: [14209]: utils: cars_shellcfg.c[118] [admin]: Invoked carsGetConsoleConfig&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I see no message that the admin user logged off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried enabling "debug all" and I can see the logged in users via "show users" but I need some sort of log message so I can track and audit the log in attempts.&amp;nbsp; It would also be nice to&amp;nbsp; see password failure attempts which I don't see either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&amp;nbsp; Can the CLI of ACS 5.4 be configured to log this information?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-cli-logging/m-p/2208277#M112381</guid>
      <dc:creator>webstert</dc:creator>
      <dc:date>2019-03-11T03:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 CLI logging</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-cli-logging/m-p/2208278#M112419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I think you're after is the ACS's "ACSManagementAudit.log" file which is stored in /opt/CSCOacs/logs/ and accessed via the "show ACS-logs" CLI command. This should show you all ACS GUI and CLI Admin Activities...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 08:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-cli-logging/m-p/2208278#M112419</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-06-14T08:12:01Z</dc:date>
    </item>
  </channel>
</rss>

