Show logging commands?

Hi guys, I m using ACS 3.3 version of windows, these are the commands

accounting AAA periodic update 1

AAA accounting exec default start-stop Ganymede group.

orders accounting AAA 15 by default start-stop Ganymede group.

but I m receive all connected show commands, I usually I record the show running, see commissioning, but no other show commands don't like to see memory int ip and others, what is the reason? How can I get orders exec connected?

Thank you

Françoise

The command that you have configured:

orders accounting AAA 15 by default start-stop Ganymede group.

will generate accounting entries for entered orders requiring level 15 privileges (such as show run, show early, etc) but don't generate accounting for orders requiring only level 1 privilege (such as sh ip int brief, etc.). If you also want these controls to generate accounting documents, then you must add this to your config:

orders accounting AAA 1 by default start-stop Ganymede group.

HTH

Rick

Tags: Cisco Security

Similar Questions

  • Cannot see the settings > Administration > manage Sessions > show log

    Hello!

    I use tables of aggregation and to check if they work well, I have to check the sql statement. But in the response "settings > Administration > manage Sessions > show log ', I see: cannot find the story

    Do you know why I can't see my sql statement? Thank you

    Hello

    I think you dint turn on query logging...

    in your SPR open your user name and of the logging level, select 2 or 1.

    before that, you need to activate a thing.

    REF here
    http://dbperf.com/Using_the_OBIEE_Log_File

    Thank you
    Knani

  • Logging commands

    If I don't have "aaa accounting command" set up, will I still be able to capture all the commands entered if I have my debug logging traps the value? that is, what is the significant difference between the two? Only two methods reached the same goal? Thank you!

    No, the debugging will not record commands typed. Debugging loggera just about everything what ele and record a message saying that the device has been configured by xxx when you exit the config, but it shows all the commands. The only way I know to do is with aaa accounting.

    -Eric

  • A brief PIX to SHOW RUN command

    For now, my pix will show the entire config in one fail swoop. I need to break it down to as many lines. I tried goggling it but no luck so far. I need to change it and make it permanent so that whenever I open up it will stay at that level?

    Please give me a link to the appropriate command or a suggestion on how to do it?

    Hello

    In Pix 6.x, you could use

    Pager

    http://www.Cisco.com/en/us/docs/security/PIX/pix63/command/reference/Mr.html#wp1026890

    Pix 7.x and higher,

    Terminal pager

    Kind regards

    Arul

    * Rate pls if it helps *.

  • Re: Vista doesn't show log on screen - Satellite P200-1K9G

    I have a Toshiba Satellite P200 1K9G.

    When I start my laptop, watch the boot screen, then the Vista loading screen displays and then not much after that, sometimes, I get my mouse cursor appears, but that's all.
    I can't open a session, because the log on screen simply does not appear.

    I fear that this may be a hardware problem... rather than a problem with Vista, although I have not made major changes that should affect the way it starts. I did however, download the latest ATI drivers, but after a reboot, it doesn't seem to be a problem.

    In addition, my laptop recently started producing a static sound if no sound was produced through a program, i.e. iTunes.

    I tried to start in Safe Mode, but my knowledge of computers is limited, can someone help me?

    Kind regards
    Trib

    Hello

    You can try using the Advanced Boot Menu.
    If you press F8 immediately after that the laptop was turned on then an advanced boot menu should appear offering boot options more.

    One of the options should be the last known good Configuration (Advanced)
    Check if you can use this option.
    More details can be found here on this page of MS:
    http://windowshelp.Microsoft.com/Windows/en-us/help/f9c50a72-04EC-4088-9fd4-a4f979eef5a71033.mspx

    But in the worst cases, the laptop must be recovered again.

  • Your plugin devoplment web page shows a command to test a metric of plugins

    The command to see if metric in a plugin can collect data is:

    java-jar < Agent Directory > /pdk/lib/hq-product.jar-Dplugins.include=yourPluginName m metric

    Can I replace the metrics of word for the names of specific metrics in the plugin...

    I performed like what but he never came out and metric information... I get no error?

    Mike,

    This is in fact exactly what is expected. Your proposal, it looks like you are to understand what is happening now.  :)

    To add an indicator for the server 'Fan Status' is as simple as paste this tag to the breast of the section (it would add under the availability)


    object = "ciscoEnvMonFanState."
    Template = "${SNMP." "Template}: ${Object}: ${index}".
    indicator = "true" / >

    Now, once the plugin is reloaded, you'll have this new measure are collected. You can trigger alerts on this such that "If the State!" = 1"and you will be notified whenever the state changes.

  • AAA authorization and control logging show

    Hello guys,.

    I am running IOS 15 on some routers and using ACS version 5.3.0.40.5 for authentication and authorization.

    I would like to have a group of users to not be able to access the configuration mode but deliver all show commands.

    However, the show logging command doesn't seem to work in user mode.

    Ideas or workarounds are welcome.

    Thanks in advance.

    Is your set command looks like him below listed link for read-only access

    http://www.security-solutions.co.za/Cisco-ACS-5.2-role-based-authentication-authorization-for-different-privilege-levels-configuration-example.html#_Toc299569579

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • Help with logs on Cisco router

    First of all: if I'm in the wrong place, please let me know.

    Question: I'm digging orders Cisco, but the help of Cisco, Googe, Yahoo Sites and other types of resources can not give me the answer I wanted.

    Router: Cisco 7206VXR (NPE - G1) processor (revision C) with 983040K / 65536K bytes of memory.

    My question is simple and pleasant: I need to learn from the history of the Interface of one of our routers and not being is not in the domain of Cisco for a few years I can't find command. If I can find a command that draws a complete history that would be great.

    The commands I used:

    history

    history of show

    car1. Ash #sh interfaces se1/0/23:0 history
    ^
    Invalid entry % detected at ' ^' marker.

    car1. Ash #show interface se1/0/23:0 60 minutes story
    ^
    Invalid entry % detected at ' ^' marker.

    I need to find the command that gives newspapers the following type:

    00:00:46: % LINK-3-UPDOWN: Interface Port-Channel, 1 changed State to
    00:00:47: % LINK-3-UPDOWN: Interface GigabitEthernet0/1, changed State to
    00:00:47: % LINK-3-UPDOWN: Interface GigabitEthernet0/2, changed State to
    00:00:48: % LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, state change downstairs
    00:00:48: % LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed
    State down 2 * 1 Mar 18:46:11: % SYS-5-CONFIG_I: configured from console by vty2
    (10.34.195.36)
    18:47:02: % SYS-5-CONFIG_I: configured from console vty2 (10.34.195.36)
    * 18:48:50.483 Mar 1 UTC: % SYS-5-CONFIG_I: configured from console vty2 (10.34.195.36)

    What you are looking for is not available using interface show orders but would be available using the show log command. You want something that could look like this

    view Journal | include 1/0/23:0

    Note that this is the search through the buffer of logging on the router. The amount of memory allocated to the record buffer and the volume of messages generated will determine how far back you can go. If the router sends syslog messages to a syslog server (or another feature of management that archive messages) then you can search the logs it and to go further back. Also note that the logging buffer is cleared when the router reloads.

    HTH

    Rick

  • Access privilege to show command run in privilege level 3 user

    I have a Dell 6248 switch. I created some users with privilege level 3. Now, I want to give users permission to the "show run" command.

    Can anyone help me how can we provide access to "'show run ' order to these users?"

    Kind regards
    Mukesh Kumar
    Network engineer
    Spooster COMPUTER services

    The PowerConnect OS doesn't have the function to specify a privilege level and assign what allows to have access to this level. The privilege levels are pre set on 0 1 read access and full access 15 block.

  • Cisco ACS 3.1 and Logging of Nortel Passport CLI commands

    Good afternoon

    We try to log commands CLI Cisco ACS version 3.1 of Nortel Passport 8600. The version of the code that runs on the Passport does not support Ganymede +.

    Passports authenticate OK but don't sign any order information. I "think" the problem is maybe that the VSA Radius of Nortel for cli-commands-attribute, 195, is not collected by ACS.

    Does anyone know how I would go to get this added to the existing list of Radius (Nortel) VSA?

    Thank you very much

    Kind regards

    Flett.

    Foisy,

    You must add the attribute Nortel 193-195 to activate the posting of the order.

    Unfortunately you can't download on code 3.x, you will need to upgrade acs to the 4.x code.

    Kind regards

    ~ JG

    Note the useful messages

  • Oracle diagnostic Log Analyzer ADF ask don't not showing life cycle phase JSF

    Hello

    I'm under JDeveloper 11.1.1.7 and run a web application through the Weblogic Server integrated. I'm trying to view the logs in the lifecycle phase JSF as they show in the Fusion of the ADF for 11.1.1.7 Developer's Guide (section 31.5).

    temp_analyzer.png

    I see in the developer's Guide that you configure logging for these packages, I did: oracle.adf (Java: more BEAUTIFUL, ODL:TRACE:32), oracle.jbo (Java: CONFIG, ODL:NOTIFICATION:16), oracle.adfinternal (Java: INFO, ODL:NOTIFICATION:16). Is to show log for me messages, but not the life cycle phase JSF:

    MyAnalyzer.png

    What I have to to get the phases of life cycle JSF to show the value?

    Thank you

    Steve

    I realized my mistake. I had put the internal logging ODL for oracle.adfdtlevel to NOTIFICATION: 16 instead of oracle.adfinternal. Updated the log levels and now I get the phases of the life cycle JSF, and ADF.

    Steve

  • How to set up the SRI 4000-4331 to enable logging of rsyslog facilitated by using the console admin GigabitEthernet0 port

    Does not work?  Pleas advise

    Run the following on the SRI 4331.

    ntmhomes #configurer t
    Enter configuration commands, one per line. End with CNTL/Z.
    ntmhomes (config) #service timestamps log datetime localtime
    ntmhomes (config) #.
    ntmhomes (config) #.
    ntmhomes (config) #logging host 192.168.20.5
    #logging ntmhomes (config) trap inform
    ntmhomes (config) #logging trap information
    FAC #logging ntmhomes (config)
    ntmhomes (config) #logging facility local7
    ntmhomes (config) #end
    ntmhomes #.

    ntmhomes (config) #logging facility local7
    ntmhomes (config) #end

    ntmhomes #show logging
    Syslog logging: activated (0 messages fell, 11 messages limited rate, 0 flashes of heat, 0 overruns, xml disabled, filtering of persons with reduced mobility)

    No discriminator Message Active.

    No discriminator inactive Message.

    Recording console: level of debugging, 50 messages, xml, disabled,.
    filtering of persons with reduced mobility
    Monitor logging: debug, 0 messages level, xml, disabled,.
    filtering of persons with reduced mobility
    Logging buffer: level of debugging, 64 recorded messages, xml, disabled,
    filtering of persons with reduced mobility
    Exception logging: size (4096 bytes)
    County and logging messages timestamp: disabled
    Persistent logging: disabled

    No active filter module.

    Logging trap: information level, 66 lines of journaled message
    Connection to 192.168.20.5 (514, auditing disabled, udp port
    (link to top),
    5 lines of message logged,
    0 message rate lines limited.
    0 message lines a dropped-by-MD,.
    Sequence number of XML disabled, disabled
    filtering of persons with reduced mobility
    Interface-logging Source: VRF name:

    Log buffer (4096 bytes):
    g to host 192.168.20.5 port 0 CLI request Triggered
    * 9 January 17:45:27: % SYS-5-CONFIG_I: configured from the system memory
    * 9 January 17:45:27: % IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/0, disabled interfaces
    * 9 January 17:45:27: % IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/1, interfaces disabled
    * 9 January 17:45:27: % SPA_OIR-6-OFFLINECARD: SPA (ISR4331-3x1GE) offline in subslot 0/0
    -More-

    I think you need to tell the system that you are using the management interface

    Try

    host 192.168.20.5 record vrf Mgmt-intf

    See the link below the section on management tasks common gigabit ethernet

    http://www.Cisco.com/c/en/us/TD/docs/routers/access/4400/software/config...

  • Pitfalls of Logging IOS - default configuration?

    Log configured by default on IOS 12.1 and above traps? If so, the default debug value? for example, if you don't see 'logging trap' in the config file - this does not mean logging is NOT enabled. Opening session, logging traps are by default configs - logging in buffered memory is not. Answer please if you can confirm this - thank you!

    Hello

    Logging settings can vary with the version of IOS. I can tell you, "logging console debugging" is enabled by default in most of the IOS versions. 'consignment of information trap' and "no logging not stamped" may be the default with most of the versions.

    Rather than trying to look for documentation see what that default value to recovery with different versions parameter record, well, we recommend that you use the command 'Show log' to check the status of the different types of logging and it will look something like this.

    Journal of #show R1

    Syslog logging: activated (0 messages fell, 1 messages limited rate, 0 flashes,

    0 overruns, disabled xml)

    Recording console: level 34 messages saved, debugging, xml disabled

    Monitor logging: level 0 messages saved, debugging, xml disabled

    Logging buffer: disabled disabled xml

    Logging size Exception (4096 bytes)

    County and logging messages timestamp: disabled

    Logging trap: informational level, 38 lines of journaled message

    All of the above settings are by default in this router running IOS version 12.2.

    HTH

    Sundar

  • view the log by using the time field a date of last year start date

    As the new year begins, I notice that if I try to do a 'show log beginning December 28 00:00:00 ' to get all the logs that surrounds an event of last week, I get no results. Most likely because the router's view I want newspapers beginning December 28, 2016, who has not yet arrived.  This command must be modified to use the * last * appearance of the starting date, not the date of beginning of this calendar year.

    This has been fixed in 5.2.3 and 5.3.0 increase CSCud91074

    Thank you

    Sam

  • How to get out the show process

    in Vshield when you do a show process or show log how you quit at a command prompt?

    to exit the show process and show log, just press q.

    Manager > show process (enter)

    you will be displayed with console process, just press q to exit.

Maybe you are looking for