cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
401
Views
0
Helpful
2
Replies

How to configure audit logs for user device deactivation/ deletion

Auditor
Level 1
Level 1

Is there a way to obtain logs to identify when a user device was added/ deleted from a Cisco wireless controller? If so, how to configure such logs?

2 Replies 2

marce1000
VIP
VIP

 

  - Usually you will not have users on a WLC directly but through external repositories , frequently accessed through radius , like for instance through ISE for instance, the question then falls back to those platforms holding the user database(s).

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

IOS-XE (9800) logs that by default in the syslogs depending on what level of logging you have configured.
%CLIENT_ORCH_LOG-7-CLIENT_MOVED_TO_RUN_STATE and %CLIENT_ORCH_LOG-7-CLIENT_MOVED_TO_DELETE_STATE amongst others.

Haven't checked myself but you could probably configure traps if you wanted to - at your own risk because will generate a lot of traps.

On AireOS you can configure SNMP traplogs - same warning as above.  Will flood your management system with traps and create CPU load on the controller.

Of course if you just want to watch a specific device you could enable debugs for that MAC address.

Review Cisco Networking for a $25 gift card