10-30-2013 10:18 AM - edited 03-16-2019 08:09 PM
Hello.
We are three admins of CUCM 8.5 and we use the same administrator user but with different ip's.
My question is:
Is there any way to know from what ip a DN was erased?.
Thanks in advance.
10-30-2013 11:02 AM
Hi reg_cisco,
Yes, you can identify the actions by IP address.
Take a look on this recently extracted Audit Log from my CUCM:
15:57:57.819 |LogMessage UserID : ccmadmin ClientAddress : 10.55.48.23 Severity : 3 EventType : UserLogging ResourceAccessed: Cisco Trace Collection Server EventStatus : Success CompulsoryEvent : No AuditCategory : AdministrativeEvent ComponentID : Cisco CCM Application AuditDetails : Login Authentication Successful App ID: Cisco Tomcat Cluster ID: Node ID: XXXXXXXXXX
10-30-2013 09:43 PM
Just in case, use RTMT to get the audit logs, and go to TRACE & LOG Central>audit logs
=============================
Please remember to rate useful posts, by clicking on the stars below.
=============================
10-31-2013 05:03 AM
@Victor, @minkdennis.
I have no enabled logs on my CUCM and I need watch a log of past days.
I don't see the option in RTMT to collect logs of past days.
@Victor I see in your example log that is not valid for my case.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide