<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can use either RADIUS or TACACS (with IMC's TAM if yo... in IMC</title>
    <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010777#M525</link>
    <description>You can use either RADIUS or TACACS (with IMC's TAM if you like) for centralised access control.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now, if we used SNMP traps, we can immediately escalate those to alarms. Since it's syslog, we need to go through another step. Bear with me, and we'll work through it in stages.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;First you need to define a Syslog Template. This will match specific patterns in the syslog entries. We can later use this template to create alarms. Once we can create alarms, we should be able to turn those into emails.&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Go to Alarms -&amp;amp;gt; Syslog Management -&amp;amp;gt; Syslog Templates. Click Add, and give it a name, and Template Content. This is the patterns to match in the syslog entry. Note that you can grab specific parts of the syslog, and assign them to parameters. For now, maybe just keep it simple. If your syslog entry looks something like this: "User admin logged in via console", then you could have a pattern Template Content like: "User $(user) logged in via $(interface)"&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Click OK to save that.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now go to "Syslog to Alarm". Click Add. Give it a name &amp;amp;amp; Description. Key things to change here are the Alarm Level, and the Repeat interval/repeat time. The default is to only generate an alarm for 50 events in 300s. You probably want 1 event in 1s. Set the severity to whatever you want.&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;In the "Alarm Description" field, just leave it as %syslog% for now. Later you can change the message if you like, using some of those parameters we got earlier. Select a Syslog Template - use the one you defined earlier. Hit OK on that.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now try triggering some of the events that cause that syslog. See if you can see the entry in "Browse Syslog". Then go and check "Alarm Browse -&amp;amp;gt; Real-Time Alarms", and see if you can see the alarm there.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Get that working, then we'll look at generating emails.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;</description>
    <pubDate>Wed, 27 Mar 2013 08:29:24 GMT</pubDate>
    <dc:creator>LindsayHill</dc:creator>
    <dc:date>2013-03-27T08:29:24Z</dc:date>
    <item>
      <title>Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6006581#M505</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we have local user (admin) in the switch 4800G and 2900al I want to see what the configure he change from iMC we have 70 switch I want to see them all in the same time not go to switch's one by one to see the log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2013 09:48:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6006581#M505</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-24T09:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6006811#M510</link>
      <description>&lt;P&gt;If I'm understanding it right, what you want to do is to generate a report that shows you all changes, across all devices (or maybe a group of devices). Is that correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think that this capability currently exists. It's easy enough to see what's changed on an individual device basis, but it's not so easy to generate a single report showing changes across all devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't dug into the ProCurve options around logging commands, but you may be able to get the switches to log all executed commands to your syslog server. I know you can do it with IOS, so it should be possible on HP switches. Set the syslog server to be the IMC system, and you'll be able to see the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should also be using centralised AAA, so you can control users, and log all commands. Then set up an alert whenever someone logs in with a local admin account, rather than using AAA.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2013 22:26:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6006811#M510</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-24T22:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007475#M511</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think you don't understand me I mean by local user in the switch not a computer user I want to know what the change in group&amp;nbsp; of (switch's) in configure like vlan , inter disable,...&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can I Set the syslog server to be the IMC system ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to use &lt;SPAN class="cmn_normalBoldFont"&gt;Configuration Templates&lt;/SPAN&gt; I add new &lt;SPAN class="cmn_normalBoldFont"&gt;Template the configure for the &lt;SPAN class="cmn_normalBoldFont"&gt;Template &lt;/SPAN&gt;you can see it in the attachment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;Thank you for your help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 05:47:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007475#M511</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-25T05:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007527#M512</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1262575"&gt;@MohammadH&lt;/a&gt; wrote:&lt;P&gt;I think you don't understand me I mean by local user in the switch not a computer user I want to know what the change in group&amp;nbsp; of (switch's) in configure like vlan , inter disable,...&amp;nbsp; ,&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wasn't referring to a computer user - I was referring to users logging into the switches or routers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1262575"&gt;@MohammadH&lt;/a&gt; wrote:&lt;P&gt;how can I Set the syslog server to be the IMC system ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to use &lt;SPAN class="cmn_normalBoldFont"&gt;Configuration Templates&lt;/SPAN&gt; I add new &lt;SPAN class="cmn_normalBoldFont"&gt;Template the configure for the &lt;SPAN class="cmn_normalBoldFont"&gt;Template &lt;/SPAN&gt;you can see it in the attachment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;Thank you for your help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;Config to set the syslog destination on a Comware-based switch would look something like:&lt;/P&gt;&lt;PRE&gt;info-center enable
info-center loghost 10.1.1.200
info-center source default channel loghost log level information
info-center source default channel loghost trap level information
info-center source default channel loghost debug state off&lt;/PRE&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In general, if you want to look at logs across a range of devices, you don't log into them all and go "display log" - instead, you configure them to all send syslogs to a central destination, and you search there. Using config templates in IMC is more intended for pushing out configuration changes, rather than looking at logs.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 06:25:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007527#M512</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-25T06:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007605#M513</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;sorry I misunderstand you&lt;/P&gt;&lt;P&gt;thank you for the configure can I have the configure for 2900 and do I need change any sitting in iMC so he can get the log from the switch ? I want to ask can make the iMC send email if the user change the configure in the switch's ??&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 07:34:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007605#M513</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-25T07:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007623#M514</link>
      <description>&lt;P&gt;On ProCurve, the commands are something like:&lt;/P&gt;&lt;P&gt;logging 10.1.1.100&lt;/P&gt;&lt;P&gt;logging severity info&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IMC will be set up to receive syslogs by default, BUT you may need to check your firewall on your server, to ensure it allows inbound syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once IMC is receiving syslogs, you should see syslogs at Alarm -&amp;gt; Syslog Management -&amp;gt; Browse Syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the switches are configured to send SNMP traps to the IMC server, and they send SNMP traps for config changes, that will generate alarms, which you can use to send emails. Those will just be generic alerts every time someone enters config mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want more complex alerts, you can configure syslog templates to match specific patterns, configure syslog to alarm escalation, and configure email alerts based on those.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 07:53:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6007623#M514</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-25T07:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009001#M517</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;thank you for configure for the ProCurve, are you by (&lt;FONT color="#FF0000"&gt;If the switches are configured to send SNMP traps to the IMC server&lt;/FONT&gt;)&lt;/P&gt;&lt;P&gt;you mean the config for the syslogs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 05:43:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009001#M517</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-26T05:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009041#M518</link>
      <description>No, SNMP traps are configured separately to syslogs. They are different protocols, used for different purposes (although I guess there is some overlap in use/functionality).&lt;BR /&gt;&lt;BR /&gt;You might want to do some reading on SNMP, and traps, and how they work in general. Might make it a bit clearer.</description>
      <pubDate>Tue, 26 Mar 2013 06:14:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009041#M518</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-26T06:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009129#M519</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I know what the SNMP traps I want to know how to config the switch and iMC so if someone login to switch or change the config or the login fail or successful the iMC will send Email &lt;SPAN class="cmn_normalFont"&gt;Notification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;I try to do it but No luck...!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;&lt;BR /&gt;and&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;Thank you for your help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 06:52:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009129#M519</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-26T06:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009153#M520</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/1262575"&gt;@MohammadH&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;I want to know how to config the switch and iMC so if someone login to switch or change the config or the login fail or successful the iMC will send Email &lt;SPAN class="cmn_normalFont"&gt;Notification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;OK. Let's start from the top. If you want an email on all logins, and config changes, then let's start by using syslog.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the switches themselves, when you login and make a change, does it display anything in your syslogs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Deal with that first. You may need to change the configs. I haven't looked into it for Comware/ProCurve, but Cisco switches need configuration to log failed login atempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once that's working, make sure that the switches are sending syslogs to the IMC server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you've got syslog entries for logins + config changes being sent to the IMC server, and visible in Alarms -&amp;gt; Syslog Management, come back here, and we'll walk through turning those syslog entries into emails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other thing you should be doing is implementing centralised AAA. This will give you MUCH better visibility and control.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 07:07:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009153#M520</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-26T07:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009549#M521</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if you mean by implementing centralised AAA the &lt;SPAN class="st"&gt;&lt;SPAN&gt;RADIUS server if that so we plan it in the future to install &lt;SPAN class="st"&gt;&lt;SPAN&gt;RADIUS &lt;/SPAN&gt;&lt;/SPAN&gt;server,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;I finish configure in the switch when I change the config in the switch I can see it in the :&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;(Alarm -&amp;gt; Syslog Management -&amp;gt; Browse Syslog),&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;so what the next step ?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;and&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="st"&gt;&lt;SPAN&gt;thank you for your help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2013 10:51:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6009549#M521</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-26T10:51:28Z</dc:date>
    </item>
    <item>
      <title>You can use either RADIUS or TACACS (with IMC's TAM if yo...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010777#M525</link>
      <description>You can use either RADIUS or TACACS (with IMC's TAM if you like) for centralised access control.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now, if we used SNMP traps, we can immediately escalate those to alarms. Since it's syslog, we need to go through another step. Bear with me, and we'll work through it in stages.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;First you need to define a Syslog Template. This will match specific patterns in the syslog entries. We can later use this template to create alarms. Once we can create alarms, we should be able to turn those into emails.&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Go to Alarms -&amp;amp;gt; Syslog Management -&amp;amp;gt; Syslog Templates. Click Add, and give it a name, and Template Content. This is the patterns to match in the syslog entry. Note that you can grab specific parts of the syslog, and assign them to parameters. For now, maybe just keep it simple. If your syslog entry looks something like this: "User admin logged in via console", then you could have a pattern Template Content like: "User $(user) logged in via $(interface)"&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Click OK to save that.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now go to "Syslog to Alarm". Click Add. Give it a name &amp;amp;amp; Description. Key things to change here are the Alarm Level, and the Repeat interval/repeat time. The default is to only generate an alarm for 50 events in 300s. You probably want 1 event in 1s. Set the severity to whatever you want.&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;In the "Alarm Description" field, just leave it as %syslog% for now. Later you can change the message if you like, using some of those parameters we got earlier. Select a Syslog Template - use the one you defined earlier. Hit OK on that.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Now try triggering some of the events that cause that syslog. See if you can see the entry in "Browse Syslog". Then go and check "Alarm Browse -&amp;amp;gt; Real-Time Alarms", and see if you can see the alarm there.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;Get that working, then we'll look at generating emails.&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;&lt;BR /&gt;&amp;amp;nbsp;</description>
      <pubDate>Wed, 27 Mar 2013 08:29:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010777#M525</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-27T08:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: lindsayhill</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010963#M526</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I want to ask the do I need active directory with TACACS ? If so is there a way to use&amp;nbsp;TACACS&amp;nbsp; without active directory ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;will the (&lt;FONT color="#FF0000"&gt;User $(user) logged in via $(interface)&lt;/FONT&gt;) work with telnet ?? or only the console ?! Because I try it whit telnet but can't see anything in (&lt;FONT color="#FF0000"&gt;Alarm Browse -&amp;gt; Real-Time Alarms&lt;/FONT&gt;) ?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have &lt;SPAN class="cmn_normalBoldFont"&gt;Filtering Trap will it effect the syslog ? I have attachment you can see the Trap.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cmn_normalBoldFont"&gt;Thank you for your help.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 07:59:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010963#M526</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-27T07:59:52Z</dc:date>
    </item>
    <item>
      <title>I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010987#M527</link>
      <description>I haven't used TAM, so I can't comment on that. You'd have to read the docs.&lt;BR /&gt;&lt;BR /&gt;That template example was just a random example - I don't know what your syslogs patterns look like. You need to look at your syslogs, and come up with a pattern that works.</description>
      <pubDate>Wed, 27 Mar 2013 08:29:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6010987#M527</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-27T08:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011035#M528</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I try to change the template but no lock, the syslogs patterns you can see it in the attachment,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 09:04:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011035#M528</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-27T09:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011041#M529</link>
      <description>So what settings do you have for your syslog template, and your syslog to alarm policies?&lt;BR /&gt;&lt;BR /&gt;Looking at those logs, you could probably also use snmp traps if you wanted.</description>
      <pubDate>Wed, 27 Mar 2013 09:15:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011041#M529</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-27T09:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011155#M530</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I look at them and I try different&amp;nbsp;&lt;SPAN class="cmn_normalBoldFont"&gt;Template Content&lt;/SPAN&gt; but no louk I will try again then come back here if it work.&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;Thank you for your help so much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 10:21:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011155#M530</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-03-27T10:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011985#M532</link>
      <description>&lt;P&gt;My advice would be to start simple with your templates. Don't worry about parameters, etc. just yet. Keep it simple, until you know you're matching what you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. for the Failed Login syslog, I might just look for "h3cLoginAuthenFailure"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that your syslog to alarm template changes the counters too, to alarm for every message, not for the default of 50 messages received in 5 minutes.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2013 23:00:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6011985#M532</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2013-03-27T23:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help in local-user and iMC.......</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6013703#M534</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On comware devices (4800), you can enable shell logging to a specific syslog server. This means that all typed commands (as shown in the local log file with display logging) can be sent to an external syslog server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not want these on the default syslog server, you can use a dedicated channel (output channel), disable all other features (default), and enable the SHELL source on this new channel.&lt;/P&gt;&lt;P&gt;Next configure a specific syslog IP for this channel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would be a sample config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;info-center channel 6 name loghostshell&lt;BR /&gt;info-center source default channel 6 log state off trap state off&lt;BR /&gt;info-center source SHELL channel 6&lt;BR /&gt;info-center loghost 192.168.5.42 channel 6&lt;BR /&gt;&lt;BR /&gt;This is not possible on provision devices. For these you need to configure an external radius server for login. The provision switches can use radius accounting to log all operator commands to an external system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached a configuration guide I have made in the past which explains the steps with a microsoft NPS radius server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Best regards,Peter.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2013 20:50:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6013703#M534</guid>
      <dc:creator>Peter_Debruyne</dc:creator>
      <dc:date>2013-03-28T20:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: I haven't used TAM, so I can't comment on that. You'd hav...</title>
      <link>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6023173#M552</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="UserName lia-user-name"&gt;&lt;SPAN class="login-bold"&gt;northlandboy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;sorry I take long time, I make it work but only send email the first time I login but sometime not send email and same for the command when I input any command it only send the first command then will not send any email so it almost work,&lt;/P&gt;&lt;P&gt;I use more then one templates for login and and logout, for the command change:&lt;/P&gt;&lt;P&gt;for the login:&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;&amp;lt;h3cLogIn&amp;gt;: $(UserName) login from VTY&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;$(UserName) logged in from $(Source IP).&lt;/P&gt;&lt;P&gt;------------------------------------------&lt;/P&gt;&lt;P&gt;for the logout:&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;&amp;lt;h3cLogOut&amp;gt;: $(UserName) logout from VTY &amp;nbsp;&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;&amp;lt;h3cLogInAuthenFailure&amp;gt;: $(UserName) failed to login from VTY, reason is 2&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;TELNET user $(UserName) failed to log in from $(Source IP) on VTY0&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;$(UserName) logged out from $(Source IP).&lt;/P&gt;&lt;P&gt;-----------------------------------------------------&lt;/P&gt;&lt;P&gt;for the cammad change:&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P&gt;-Task=vt0-IPAddr=$(Source IP)-User=$(UserName); Command is&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;$(Source IP)-User=$(UserName); Command is&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name"&gt;&lt;SPAN class="login-bold"&gt;hi Peter_Debruyne&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thank you for the guide it really help me , and for the config sample.&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for taking your time to help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 05:48:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/help-in-local-user-and-imc/m-p/6023173#M552</guid>
      <dc:creator>MohammadH</dc:creator>
      <dc:date>2013-04-08T05:48:55Z</dc:date>
    </item>
  </channel>
</rss>

