Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell PowerVault ME5 Series Storage System CLI Reference Guide

PDF

show audit-log

Description Shows audit log data.

All user login and logout attempts and operations performed through the CLI, PowerVault Manager, and FTP/SFTP interface are recorded in the audit log. Failed login attempts are also recorded.

The audit log will contain the timestamp, username, and command that was run as well as the status code returned by that command. The audit log contains a subset of the data that is stored in controller logs. The audit log will not contain specific value changes, such as old and new settings.

Audit logs record host IP information for all interfaces. Audit logs also record snmpset commands.

Each controller maintains its own audit log. Each audit log can contain up to 2MB of data, after which it will wrap.

Audit log data will persist after restarting the Storage Controller or running the restore defaults command. Audit logs are not associated with the managed logs feature. Audit logs will be cleared during factory refurbishment.

Audit log data is not mirrored to the partner controller. In a failover scenario, the failed controller's audit log cannot be retrieved until the failed controller is recovered. When the failed controller comes back online its audit log should be accessible.

Minimum role monitor
Syntax show audit-log

[a|b|both]

[last <number-of-entries>]

Parameters a|b|both

Optional. Specifies to show the audit log for controller A, B, or both. If this parameter is omitted, the audit log is shown for the current controller.

last <number-of-entries>

Optional. Shows the specified number of most recent entries. If this parameter is omitted, all events are shown.

Output

All audit log entries for the specified controller(s) are listed in chronological order by date and time. An entry may contain the following fields:

  • Date and time
  • Facility ID and name (for internal use)
  • Process
  • C: Controller ID
  • UID: Username
  • GID: Group name, or "-" if not supported
  • SID: Session ID
  • A: Action
  • SSID: MC subsystem ID
  • RC: Return code
  • M: Message

The session ID is logged only when authentication is successful and a session has been created. The subsystem ID and return code are for diagnostic purposes.

Examples Show the audit log for controller B only.

# show audit-log b

Basetypes

audit-log

status

See also show user-groups

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\