Audit authenticated sessions
-
Log type. The logs can be stored remotely (syslog) or locally on NetScaler (nslog).
-
Rule. The conditions on which the logs are stored.
-
Action. Details of the log server and other details for creating the log entries.
To configure syslog auditing by using the CLI
-
Configure the audit server with the relevant log settings.ns-cli-prompt\> add audit syslogAction \<name\> \<serverIP\> ...
-
Configure the audit policy by associating the audit server.ns-cli-prompt\> add audit syslogPolicy \<name\> \<rule\> \<action\>
-
Associate the audit policy with one of the following entities:
-
Bind the policy to a specific user.ns-cli-prompt\> bind aaa user \<userName\>-policy \<policyname\> ...
-
Bind the policy to a specific group.ns-cli-prompt\> bind aaa group \<groupName\>-policy \<policyname\> ...
-
Bind the policy to an authentication, authorization, and auditing virtual server.ns-cli-prompt\> bind authentication vserver \<name\> -policy \<policyname\> ...
-
Bind the policy globally to NetScaler.ns-cli-prompt\> bind tm global -policyName \<policyname\> ...
-
To configure syslog auditing by using the GUI
-
Configure the audit server and policy.Navigate to Security > AAA - Application Traffic > Policies > Auditing > Syslog, and configure the server and the policy in the relevant tabs.
-
Associate the audit policy with one of the following:
-
Bind the audit policy to a specific user.Navigate to Security > AAA - Application Traffic > Users, and associate the audit policy with the relevant user.
-
Bind the audit policy to a specific group.Navigate to Security > AAA - Application Traffic > Groups, and associate the audit policy with the relevant group.
-
Bind the audit policy to an authentication, authorization, and auditing virtual server.Navigate to Security > AAA - Application Traffic > Virtual Servers, and associate the audit policy with the relevant virtual server.
-
Bind the audit policy globally to NetScaler.Navigate to Security > AAA - Application Traffic > Policies > Auditing > Syslog or Nslog, select the audit policy, and click Action > Global Bindings to bind the policy globally.
-