DELL 9.7(0.0) User Manual

Page of 1039
• The network administrator and network operator user roles can view system events.
NOTE: If extended logging is disabled, you can only view system events, regardless of RBAC user 
role.
Example of Enabling Audit and Security Logs
Dell(conf)#logging extended
Displaying Audit and Security Logs 
To display audit logs, use the show logging auditlog command in Exec mode. To view these logs, 
you must first enable the logging extended command. Only the RBAC system administrator user role can 
view the audit logs. Only the RBAC security administrator and system administrator user role can view the 
security logs. If extended logging is disabled, you can only view system events, regardless of RBAC user 
role. To view security logs, use the show logging command.
Example of the show logging auditlog Command
For information about the logging extended command, see 
Dell#show logging auditlog 
May 12 12:20:25: Dell#: %CLI-6-logging extended by admin from vty0 (10.14.1.98)
May 12 12:20:42: Dell#: %CLI-6-configure terminal by admin from vty0 
(10.14.1.98)
May 12 12:20:42: Dell#: %CLI-6-service timestamps log datetime by admin from 
vty0 (10.14.1.98)
Example of the show logging Command for Security
For information about the logging extended command, see 
Dell#show logging
Jun 10 04:23:40: %STKUNIT0-M:CP %SEC-5-LOGIN_SUCCESS: Login successful for user 
admin on line vty0 ( 10.14.1.91 ) 
Clearing Audit Logs
To clear audit logs, use the clear logging auditlog command in Exec mode. When RBAC is 
enabled, only the system administrator user role can issue this command.
Example of the clear logging auditlog Command
Dell# clear logging auditlog 
Configuring Logging Format  
To display syslog messages in a RFC 3164 or RFC 5424 format, use the logging version [0 | 1} 
command in CONFIGURATION mode. By default, the system log version is set to 0.
The following describes the two log messages formats:
• 0 – Displays syslog messages format as described in RFC 3164, The BSD syslog Protocol
• 1 – Displays syslog message format as described in RFC 5424, The SYSLOG Protocol
Example of Configuring the Logging Message Format 
Dell(conf)#logging version ?
<0-1> Select syslog version (default = 0) 
Dell(conf)#logging version 1 
60
Switch Management