<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query: HP Synergy audit log format - ci-audit-log in HPE Synergy</title>
    <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180277#M1193</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;how can I know the IP address from where the user connect to OneView&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;So you've asked two things: which user performed the operation and what is that user's source IP where they are running their browser from (to connect to OneView).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To find out what user executed an operation, you need to see if it was part of a task and then use the RESTapi to look up more information about that task.&amp;nbsp; For example,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;2022-09-21 03:30:48.585 UTC,crm,,,System,LTk5NzY4NTQxMDMw,/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4,127.0.0.1,SUCCESS,MODIFY,INFO,logical-interconnects,/rest/logical-interconnects/ef3537c6-be26-4e05-8e07-92bd168cab44,Adding interconnect to logical-interconnect C7000_A_abajo-LIG_2SM520000F_1 at location: enclosure: /rest/enclosures/092SM520000F bay: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;You'll need to look up&amp;nbsp;/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4 using PowerShell or the RESTapi.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other entries may have the user, sometimes "Administrator" or any other authorized user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are other entries specifically corresponding to that user logging on and their source IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;2021-05-19 19:03:51.474 UTC,Authentication,,Local,Administrator,,,16.99.152.235,SUCCESS,LOGIN,INFO,AUTHENTICATION,,Authentication SUCCESS. User "Administrator" logged in successfully from client "16.99.152.235" and directory "LOCAL". [logID "MzQ2MDM3MDcyMTgy"]&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Maybe that will point you in the right direction.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2023 20:31:47 GMT</pubDate>
    <dc:creator>DanCernese</dc:creator>
    <dc:date>2023-01-05T20:31:47Z</dc:date>
    <item>
      <title>HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179416#M1176</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm looking for some manual with the description of the ci-audit-log format.&lt;/P&gt;&lt;P&gt;What I need is the meaning of&amp;nbsp;&lt;SPAN&gt;multiples descriptions for the follow columns: componentId,&amp;nbsp;result, action, severity, object and objectDescription. For example: column&amp;nbsp;componentId had different values: "licmgr", "cert", "psrm", "crm", "tasktrack"; some of them as self explained ("licmgr"), but no others.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jorge&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 07:35:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179416#M1176</guid>
      <dc:creator>JorgePizarro</dc:creator>
      <dc:date>2023-01-06T07:35:11Z</dc:date>
    </item>
    <item>
      <title>Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179418#M1177</link>
      <description>&lt;P style="margin: 0;"&gt;&lt;STRONG&gt;System recommended content:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;1. &lt;A href="https://hpe.to/66073GZ2S" target="_blank" rel="noopener"&gt;HPE OneView 8.0 User Guide for HPE Synergy |  Support dump file&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;2. &lt;A href="https://hpe.to/66043GZ2I" target="_blank" rel="noopener"&gt;HPE OneView 7.1 User Guide for HPE Synergy |  Support dump file&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Please click on "Thumbs Up/Kudo" icon to give a "Kudo".&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Thank you for being a HPE valuable community member.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 13:22:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179418#M1177</guid>
      <dc:creator>support_s</dc:creator>
      <dc:date>2022-12-14T13:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179419#M1178</link>
      <description>&lt;P&gt;Hi, can you be more specific? Page of this URL (manual)?&lt;/P&gt;&lt;P&gt;The manual (PDF File) is more than 800 pages long, I search por "crm" or "psrm" (&lt;SPAN&gt;componentId) but does not find any match.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm looking for information about meaning of follow log lines (example, extract):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-09-21 03:30:48.585 UTC,crm,,,System,LTk5NzY4NTQxMDMw,/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4,127.0.0.1,SUCCESS,MODIFY,INFO,logical-interconnects,/rest/logical-interconnects/ef3537c6-be26-4e05-8e07-92bd168cab44,Adding interconnect to logical-interconnect C7000_A_Down_2SM520000F at location: enclosure: /rest/enclosures/092SM520000F bay: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2022-09-20 19:39:18.742 UTC,psrm,,localhost,System,LTU1NjQ1MzExMDM5,/rest/tasks/A0BC322F-3448-45DE-AD0D-204097B531B2,,FAILURE,MODIFY,INFO,SERVER,/rest/server-hardware/30373237-3132-4D32-3235-343130345744,Refresh server hardware&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jorge&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:18:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179419#M1178</guid>
      <dc:creator>JorgePizarro</dc:creator>
      <dc:date>2022-12-14T14:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179687#M1179</link>
      <description>&lt;P&gt;You're correct, the "internal component names" are not documented.&amp;nbsp; In reality what they are shouldn't matter except to identify which internal component executed the action that is the remainder of the log entry.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 16:31:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179687#M1179</guid>
      <dc:creator>DanCernese</dc:creator>
      <dc:date>2022-12-20T16:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179688#M1180</link>
      <description>&lt;P&gt;Well, maybe I need to say that I'am a Digital Forensics Analyst. A customer suffer a security incidente with the FlexFabric (someone connect to it and execute some commands). All I have is the log (ciAudit.log).&lt;/P&gt;&lt;P&gt;I need to undestand what the "attacker" try to do with the executed commands in the log.&lt;/P&gt;&lt;P&gt;Some commands are self explanatory, but other not.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;"/rest/tasks/" with component-id psrm&lt;/P&gt;&lt;P&gt;"/rest/tasks/" with component-id crm&lt;/P&gt;&lt;P&gt;"Refresh server hardware"&amp;nbsp;with component-id psrm&lt;/P&gt;&lt;P&gt;"/rest/ethernet-networks/374ed2f6-8881-4267-be92-713d669b34e3,Updated ethernet-network 'Fiserv-Internet-A'"&amp;nbsp;with component-id crm&lt;/P&gt;&lt;P&gt;"Deleted connection-template 'name-1066080839-1491836372577'"&amp;nbsp;with component-id crm&lt;/P&gt;&lt;P&gt;"/rest/network-sets/832976bb-382b-45eb-beec-a8d7e6cb85f7,Updated network-set 'NetSet_2SN54116Q2_10'"&amp;nbsp;with component-id crm&lt;/P&gt;&lt;P&gt;"Updated connection-template 'name-623451695-1663732523724'"&amp;nbsp;with component-id crm&lt;/P&gt;&lt;P&gt;"Updated logical-interconnect-group 'LIG_0000000000_1'"&amp;nbsp;with component-id crm&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 16:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179688#M1180</guid>
      <dc:creator>JorgePizarro</dc:creator>
      <dc:date>2022-12-20T16:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179742#M1181</link>
      <description>&lt;P&gt;Understood-- but the component internal name won't help anyone understand what an attacker or user is trying to do or has done because everything of value is in the rest of the message. I'll share this, if you think it helps, these are definitive:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CRM == connectivity resource manager:&amp;nbsp; networks, switches, profile connections&lt;/LI&gt;&lt;LI&gt;PSRM == physical server resource manager:&amp;nbsp; enclosures, servers, and server health&lt;/LI&gt;&lt;LI&gt;PM == profile manager:&amp;nbsp; server profiles, cluster profiles, host profiles&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 21 Dec 2022 15:12:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179742#M1181</guid>
      <dc:creator>DanCernese</dc:creator>
      <dc:date>2022-12-21T15:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179892#M1182</link>
      <description>&lt;P&gt;Thanks for your responses.&lt;/P&gt;&lt;P&gt;I have another question.&lt;/P&gt;&lt;P&gt;The follow events show some activity from localhost (127.0.0.1). From what application this activity comes from?&lt;/P&gt;&lt;P&gt;2022-09-21 03:30:48.585 UTC,crm,,,System,LTk5NzY4NTQxMDMw,/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4,127.0.0.1,SUCCESS,MODIFY,INFO,logical-interconnects,/rest/logical-interconnects/ef3537c6-be26-4e05-8e07-92bd168cab44,Adding interconnect to logical-interconnect C7000_A_abajo-LIG_2SM520000F_1 at location: enclosure: /rest/enclosures/092SM520000F bay: 1&lt;/P&gt;&lt;P&gt;2022-09-21 05:07:13.836 UTC,security,,,appliance,MTMzOTQ0NDQwMjcy,,localhost,SUCCESS,DELETE,INFO,SESSION,1374d41c-76b5-491b-8084-662cf07d52a9,The session for user "appliance" with [logID:MTMzOTQ0NDQwMjcy] timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 15:28:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7179892#M1182</guid>
      <dc:creator>JorgePizarro</dc:creator>
      <dc:date>2022-12-27T15:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180121#M1187</link>
      <description>&lt;P&gt;HPE OneView&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 21:20:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180121#M1187</guid>
      <dc:creator>DanCernese</dc:creator>
      <dc:date>2023-01-03T21:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180129#M1189</link>
      <description>&lt;P style="margin: 0;"&gt;The events mentioned are captured by Oneview.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;2022-09-21 03:30:48.585 UTC,crm,,,System,LTk5NzY4NTQxMDMw,/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4,127.0.0.1,SUCCESS,MODIFY,INFO,logical-interconnects,/rest/logical-interconnects/ef3537c6-be26-4e05-8e07-92bd168cab44,Adding interconnect to logical-interconnect C7000_A_abajo-LIG_2SM520000F_1 at location: enclosure: /rest/enclosures/092SM520000F bay: 1&lt;/P&gt;
&lt;P style="margin: 0;"&gt;2022-09-21 05:07:13.836 UTC,security,,,appliance,MTMzOTQ0NDQwMjcy,,localhost,SUCCESS,DELETE,INFO,SESSION,1374d41c-76b5-491b-8084-662cf07d52a9,The session for user "appliance" with [logID:MTMzOTQ0NDQwMjcy] timed out.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 03:17:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180129#M1189</guid>
      <dc:creator>support_s</dc:creator>
      <dc:date>2023-01-04T03:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180155#M1190</link>
      <description>&lt;P&gt;As the ciAuditlog only show "localhost" for OneView user's connections, how can I know the IP address from where the user connect to OneView application?&lt;/P&gt;&lt;P&gt;From my understanding, OneView is a web application, right?&lt;/P&gt;&lt;P&gt;There are some log file for this web application?&lt;/P&gt;&lt;P&gt;Where this logs files are located?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 10:46:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180155#M1190</guid>
      <dc:creator>JorgePizarro</dc:creator>
      <dc:date>2023-01-04T10:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180217#M1191</link>
      <description>&lt;P style="margin: 0;"&gt;Usually, the HPE Oneview is configured during the installation. Please refer the installation guide below.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;A href="https://techlibrary.hpe.com/docs/synergy/shared/setup_overview/index.html" target="_blank"&gt;https://techlibrary.hpe.com/docs/synergy/shared/setup_overview/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;Also, for getting information about the environment, we usually check the CI Support Dump (For composers) and LE Support Dump.&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;LE Support Dump can be collected from Logical Enclosure on Oneview.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 05:35:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180217#M1191</guid>
      <dc:creator>Keerthana_RP</dc:creator>
      <dc:date>2023-01-05T05:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Query: HP Synergy audit log format - ci-audit-log</title>
      <link>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180277#M1193</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;how can I know the IP address from where the user connect to OneView&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;So you've asked two things: which user performed the operation and what is that user's source IP where they are running their browser from (to connect to OneView).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To find out what user executed an operation, you need to see if it was part of a task and then use the RESTapi to look up more information about that task.&amp;nbsp; For example,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;2022-09-21 03:30:48.585 UTC,crm,,,System,LTk5NzY4NTQxMDMw,/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4,127.0.0.1,SUCCESS,MODIFY,INFO,logical-interconnects,/rest/logical-interconnects/ef3537c6-be26-4e05-8e07-92bd168cab44,Adding interconnect to logical-interconnect C7000_A_abajo-LIG_2SM520000F_1 at location: enclosure: /rest/enclosures/092SM520000F bay: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;You'll need to look up&amp;nbsp;/rest/tasks/D81C5471-C22D-47AA-8FBB-8DAAAE8877C4 using PowerShell or the RESTapi.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other entries may have the user, sometimes "Administrator" or any other authorized user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are other entries specifically corresponding to that user logging on and their source IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;2021-05-19 19:03:51.474 UTC,Authentication,,Local,Administrator,,,16.99.152.235,SUCCESS,LOGIN,INFO,AUTHENTICATION,,Authentication SUCCESS. User "Administrator" logged in successfully from client "16.99.152.235" and directory "LOCAL". [logID "MzQ2MDM3MDcyMTgy"]&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Maybe that will point you in the right direction.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 20:31:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-synergy/hp-synergy-audit-log-format-ci-audit-log/m-p/7180277#M1193</guid>
      <dc:creator>DanCernese</dc:creator>
      <dc:date>2023-01-05T20:31:47Z</dc:date>
    </item>
  </channel>
</rss>

