Table Of Contents
8.1 What Is Security Management?
8.2 How Do I Customize the Login Advisory Message?
8.3 How Do I Manage User Security?
8.3.2 Viewing the Audit Trail File
8.3.4 Performing User Administration
8.4 How Do I Manage the Audit Log?
8.4.2 Filtering Audit Log Data
Managing Security
This chapter describes Cisco MGM security and how to manage users. This includes an overview of security domains and a description of the user security and NE security features available in Cisco MGM.
This chapter contains the following sections:
•How Do I Customize the Login Advisory Message?
•How Do I Manage User Security?
•How Do I Manage the Audit Log?
8.1 What Is Security Management?
Why create a security policy?
•To create a baseline of your current security posture
•To set the framework for security implementation
•To define allowed and disallowed behaviors
•To help determine necessary tools and procedures
•To communicate consensus and define roles
•To define how to handle security incidents
The following security domains govern Cisco MGM networks:
•Cisco MGM client—A Cisco MGM client must be created with one of the existing default user profiles or with a new custom user profile with appropriate access privileges. This new user profile should be created and assigned to a user.
•Cisco MGM OSS users—OSS-to-Cisco MGM sessions are configured by the Cisco MGM CORBA GateWay EMS-to-NMS interface architectural component. For more information about Cisco MGM CORBA GateWay, see "Managing CORBA Interfaces."
8.2 How Do I Customize the Login Advisory Message?
After logging into the Cisco MGM client, a login advisory message is shown. By default, the advisory message reads:
NOTICE: This is a private computer system. Unauthorized access or use may lead to prosecution.You can customize the default advisory message as follows:
Step 1 Log into the Cisco MGM server as the root user.
Step 2 Use a text editor to edit or create the advisory.txt file in the /opt/CiscoMGMServer/cfg directory. The new advisory message can contain up to 1,600 characters. The advisory.txt file does not exist by default.
Note The default directory /opt/CiscoMGMServer may have been changed during installation of the Cisco MGM server.
Step 3 Save the changes. All subsequent users who log into the Cisco MGM client will see the new advisory message.
Note You can also disable the advisory message altogether. See Configuring Cisco MGM Security Parameters.
8.3 How Do I Manage User Security?
This section describes user security and management. This includes procedures on how to add a new user, modify a user's properties, delete a user, and end an active user session. It also includes procedures on how to add, modify, and delete custom profiles and how to perform NE user administration.
The following topics are covered:
•Performing User Administration
8.3.1 Restricting User Access
The Administration > Cisco MGM Users menu launched from the Domain Explorer window manages user security. Cisco MGM administration allows restricted access logins to enable users to perform tasks based on detailed access privileges.
For each action, a user is given privileges to read to read/write. For definitions of the access privileges, see Table 8-1.
Table 8-2 lists the access privileges required to perform security-controlled operations within the Diagnostic Center application.
Table 8-2 Diagnostic Center Access Privileges
Access Privilege OperationRead
Enables get connections, test connections, connection trace, and trouble tickets attachment.
Read/Write
Enables up connections, and saves trouble tickets.
Enables the following operations at different levels:
•Node—Specifies node resync and checks manageability.
•Line and path—Applies loopback and starts and modifies BERT1 .
•Port—Starts and modifies BERT and grooming functions.
•Connections—Specifies loopback connections.
No Access
User has no access permissions.
1 BERT = Bit Error Rate Test
To perform security-controlled operations within Chassis View and Statistics Reporting Tool applications, Read is the only access privilege allowed. The Read access privilege enables all operations that are supported by the application.
8.3.2 Viewing the Audit Trail File
The Cisco MGM Audit Trail Viewer records activities across the four applications (Configuration Center, Chassis View, Statistics Reporting Tool, and Diagnostic Center) in a persistent file.
Note Audit trail logging is done per Cisco MGM workstation and each workstation performs an independent audit trail file. There is no communication or synchronization between workstations regarding an audit trail.
Using the Audit Trail Viewer, you can access audit trail files for specified days, and you can sort, filter, and search for specific log entries. All readand write activities are monitored and logged to a file. To open the Audit Trail Viewer, complete the following procedure:
Step 1 From the Cisco MGM Domain Explorer window, choose Administration > MGX 8880/8850 MG > Audit Trail.
Note If no NE is selected in the Domain Explorer, the Audit Trail option will be grayed out.
or
from the Configuration Center, Statistics Reporting Tool, Chassis View, or Diagnostic Center:
•Choose Tools > Administration > Cisco MGM Audit Trail
•Right-click on any object in the Hierarchy pane and choose Administration > Cisco MGM Audit Trail
Step 2 Enter the fields.
Note Table 8-3 describes fields in the Cisco MGM Audit Trail Viewer.
Step 3 Click Submit to submit the specified criteria for the log file.
Step 4 Click Reset All to reset all the fields to the default state.
8.3.3 User Profiles
By default, Cisco MGM contains the following user profiles:
•NetworkAdmin—Typically, NOC supervisors who perform daily network surveillance, provisioning, and performance monitoring activities on any group or NE.
•Operator—Users who perform daily network surveillance and performance monitoring activities on specific NEs. Each operator can have only one active session. Operators cannot access administrative information.
•Provisioner—Users who perform daily network surveillance, provisioning, and performance monitoring activities on specific NEs. Each provisioner can have only one active session. Provisioners cannot access administrative information.
•SuperUser—Users who have access to all operations.
•SysAdmin—System administrators who manage Cisco MGM access.
The following sections describe how to view, add, modify, delete, and duplicate a user profile:
8.3.3.1 Viewing User Profiles
The Cisco MGM User Profiles table displays basic information about Cisco MGM user profiles. Use the menu options to manage user profiles.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Cisco MGM User Profiles (or click the Launch User Profiles Table tool). Table 8-4 describes the fields in the Cisco MGM User Profiles table.
8.3.3.2 Adding a Custom User Profile
Cisco MGM allows SuperUsers and SysAdmins to generate custom user profiles with certain privileges. Custom user profiles are grouped into categories and each category has a set of operations (see Table 8-6). After the user profiles are generated, they can be assigned to new Cisco MGM users. This functionality, also known as network partitioning, allows you to control how much access particular users have to the network.
Use the Create New User Profile wizard to add Cisco MGM user profiles. Table 8-5 describes the fields in the wizard.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Cisco MGM User Profiles (or click the Launch User Profiles Table tool).
Step 3 In the Cisco MGM User Profiles table, choose Edit > Create (or click the Create a New User Profile tool).
Step 4 In the Create New Cisco MGM User Profile wizard, specify the following:
•User profile name
•NE assignment (read only)
•Default user login sessions allowed
•Description
Step 5 Click Next.
Step 6 Select a user profile category from the Categories area. Operations for each category are displayed on the right side of the Categories area. See Table 8-6 for a complete list of Cisco MGM profile categories and operations.
Step 7 Specify user capabilities by setting permission or privileges for one or all operations. When setting privileges for each operation, select one of the following radio buttons:
•Read Only
•Read/Write
•No Access
When setting privileges for all operations, select one of the following buttons:
•Set All Read Only
•Set All Read/Write
•Set All No Access
Note The user profile operations displayed on the right side of the Create New Cisco MGM User Profile wizard depend on the category selected. You can select the root node to see all the operations for all categories.
Step 8 Click Finish.
Step 9 Click Yes in the message box. The message box will not be displayed if it is disabled in the User Preferences dialog box. See Setting User Preferences for more information.
Table 8-6 Cisco MGM Custom User Profiles
Category Operations Description PrivilegesAdministration
Audit/Error Log
Launch the Audit Log and Error Log.
Read Only or No Access
Control Panel
Launch the Control Panel and related tables.
Read/Write or No Access
Logged In MGM Users
Launch the Logged In MGM Users Table.
Read Only, Read/Write, or No Access
MGM User Profiles
Launch the Cisco MGM User Profiles Table and add, delete, or modify user profiles.
Read Only, Read/Write, or No Access
MGM Users
Launch the MGM Users Table and add, delete, or modify users and user preferences.
Read Only, Read/Write, or No Access
Save Map As Default
Save map customizations as default.
Read/Write or No Access
NE Administration
Add or Delete NE or Group
Add or delete NEs or groups from the domain.
Not assigned
Audit Trail
Launch the Audit Trail Table.
Read Only, Read/Write, or No Access
Edit Domain Node Properties
Edit properties on the property sheet associated with the root node in the Domain Explorer tree.
Read/Write or No Access
Edit NE or Group Properties
Edit NE or group properties.
Read/Write or No Access
SSH Secure Shell
Command line tool to gain secure shell access to MGX switches.
Read/Write, or No Access
Supported NE Table
Launch the Supported NE Table.
Read Only, Read/Write, or No Access
Telnet session
Command line tool to telnet to MGX switches.
Read/Write, or No Access
Topology Modification
Drag, drop, cut, copy, and paste NEs in the Domain Explorer.
Not assigned
User Preferences
Edit the user preferences.
Read/Write or No Access
NE CM1
Audit Logging in Chassis View
Activates or deactivates the Audit Trail in Chassis View.
Read Only, Read/Write, or No Access
Audit Logging in Configuration Center
Activates or deactivates the Audit Trail in Configuration Center.
Read Only, Read/Write, or No Access
Chassis View
Launches the Chassis View application.
Read Only, Read/Write, or No Access
Configuration Center
Launches the Configuration Center application.
Read Only, Read/Write, or No Access
Equipment Inventory
Launches the Equipment Inventory Table.
Read Only or No Access
NE FM2
Alarm Browser/Log
Launches the Alarm Browser, Alarm Log, or Event Export Manager, acknowledge alarms, and show alarm notes.
Read Only, Read/Write, or No Access
Audit Logging In Diagnostics Center
Activates or deactivates the Audit Trail in the Diagnostics Center.
Read Only, Read/Write, or No Access
Diagnostics Center
Launches the Diagnostic Center application.
Read Only, Read/Write, or No Access
Show MGM EMS Alarms/Events
Show MGM-specific EMS alarms and events count in the Dashboard, show MGM specific EMS alarms in the Alarm Browser, and show MGM specific EMS alarms and events-related pop-ups.
Read/Write or No Access
NE Management
Audit Trail Table
Launches the Audit Trail table.
Read Only or No Access
Job Monitor
Launch the Job Monitor Table and cancel job, cancel task, add user notes, or view user notes.
Read Only, Read/Write, or No Access
NE PM
Audit Logging in Statistics Reporting Tool
Activates or deactivates the Audit Trail in the Statistics Reporting Tool.
Read Only, Read/Write, or No Access
Statistics Reporting Tool
Launches the Statistics Reporting Tool application.
Read Only, Read/Write, or No Access
1 NE Configuration Management
2 NE Fault Management
8.3.3.3 Modifying a User Profile
Use the Modify User Profile wizard to modify Cisco MGM user profiles. Table 8-5 describes the fields in the wizard.
Note Users created with a certain profile cannot be changed to another profile. To change profiles, the user must be deleted, then recreated with the new profile.
Modifying a profile will log out all users who are logged in with that profile.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Cisco MGM User Profiles (or click the Launch User Profiles Table tool).
Step 3 In the table, click the user profile name to modify; then, choose Edit > Modify (or click the Modify User Profile Properties tool).
Step 4 In the Modify Cisco MGM User Profile wizard, modify the following:
•Default user login sessions allowed
•Description
Step 5 Click Next.
Step 6 Select a user profile category from the Categories area. Operations for each category are displayed on the right side of the Categories area. See Table 8-6 for a list of Cisco MGM profile categories and operations.
Step 7 Specify user capabilities by setting permission or privileges on one or all operations. When setting privileges for each operation, select one of the following radio buttons:
•Read Only
•Read/Write
•No Access
When setting privileges for all operations, select one of the following buttons:
•Set All Read Only
•Set All Read/Write
•Set All No Access
Note The user profile operations displayed on the right side of the Create New Cisco MGM User Profile wizard depend on the category selected. You can select the root node to see all the operations for all categories.
Step 8 Click Finish.
Step 9 Click Yes in the message box. The message box will not be displayed if it is disabled in the User Preferences dialog box. See Setting User Preferences for more information.
8.3.3.4 Deleting a User Profile
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Cisco MGM User Profiles (or click the Launch User Profiles Table tool).
Step 3 In the Cisco MGM User Profiles table, select the profile you want to delete; then, choose Edit > Delete (or click the Delete User Profile tool).
Step 4 In the confirmation dialog box, click OK.
Note The default user profiles (SuperUser, SysAdmin, NetworkAdmin, Provisioner, and Operator) cannot be deleted. Custom user profiles cannot be deleted if they are assigned to any user. Delete the user with the custom user profile before deleting the user profile. See Deleting a Cisco MGM User.
8.3.3.5 Duplicating a User Profile
Use the Create Duplicate Profile window to duplicate an existing Cisco MGM user profile.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Cisco MGM User Profiles (or click the Launch User Profiles Table tool).
Step 3 In the Cisco MGM User Profiles table, select the profile you want to duplicate; then, choose Edit > Duplicate (or click the Duplicate User Profile tool).
Step 4 In the Create Duplicate Profile dialog box, enter the duplicate profile name. See Table 8-7 for name constraints.
Step 5 Click OK.
8.3.4 Performing User Administration
This section describes how to perform user administration, including:
•Managing the Cisco MGM Default User Profiles
•Viewing the Cisco MGM Users Table
•Modifying a Cisco MGM User's Properties
•Viewing Logged In Cisco MGM Users
•Ending an Active Cisco MGM User Session
•Using the Cisco MGM Locked Window
•Enabling or Disabling the Continuous Audible Alarm
•Configuring Cisco MGM Security Parameters
•Sending Messages to Other Users
•Viewing User Notification Messages
8.3.4.1 Managing the Cisco MGM Default User Profiles
Table 8-8 lists the Cisco MGM default user profiles and the privileges associated with each profile.
Note The SuperUser profile has access to all operations, and is not specifically listed in a separate column.
The NetworkAdmin profile has access to all NEs and groups. The SysAdmin profile has access to no NEs or groups.
8.3.4.2 Viewing the Cisco MGM Users Table
The MGM Users table displays basic information about Cisco MGM users. The table menu options allow you to create new users, modify users, delete users, and unlock user accounts.
To view the MGM Users table, choose Administration > Cisco MGM Users in the Domain Explorer window. Table 8-9 describes the fields in the table.
8.3.4.3 Creating a Cisco MGM User
Use the Create New MGM User wizard to add new Cisco MGM users to the domain. Table 8-10 describes the fields in the wizard.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the MGM Users table, choose Edit > Create (or click the Create a New User tool).
Step 3 In the Create New MGM User wizard, enter the following information:
•Username
•User password (and confirm password)
•User privilege
•Domain name
•Login state
•Password change
•Description
•Use Global Settings check box
•Enable check box
•Period
•User login sessions
Step 4 Click Next. When you finish adding a new SuperUser, NetworkAdmin, or SysAdmin, click Finish.
Step 5 When adding a new Provisioner, Operator, or custom user profile, select the groups and NEs that the Provisioner or Operator will monitor. Selected groups and NEs appear in the Assigned Objects list. (SuperUsers and NetworkAdmins monitor the entire management domain, so there is no need to select groups or NEs when adding one of these users. SysAdmin users do not access any of the NEs.)
a. To assign groups, click the Groups radio button. In the Available Objects list, select the groups that will be assigned to the new user and click Add.
b. To assign NEs, click the Network Elements radio button. In the Available Objects list, select the NEs that will be assigned to the new user and click Add.
Note When individual NEs are assigned, these NEs will appear directly under the top level domain for the user in the Domain Explorer. It is possible that a given NE may have already been assigned as part of a group assignment to the user. In such a case, the same NE will appear directly under the top level domain and also within the assigned group. This behavior is consistent with the Domain Explorer's ability to represent the same group or NE within multiple locations of the hierarchy.
c. To remove groups or NEs from the Assigned Objects list, select the group or NE from the Assigned Objects list and click Remove.
d. Click Next (or Finish).
Step 6 Click Finish.
The new user is listed in the MGM Users table.
8.3.4.4 Modifying a Cisco MGM User's Properties
Use the Modify MGM User Properties wizard to modify the properties of an existing Cisco MGM user. Table 8-11 describes the fields in the wizard.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, select the user whose properties will be modified.
Step 3 Choose Edit > Modify (or click the Modify User Properties tool). The Modify MGM User Properties wizard opens.
Step 4 Modify the following information, as needed; then, click Next:
•Username
•User password (and confirm password)
•User privilege
•Domain name
•Login state
•Password change
•Description
•Use Global Settings check box
•Enable check box
•Period
•User login sessions
Step 5 (Optional) For Provisioner, Operator, and custom user profiles, modify the list of assigned objects by adding groups or NEs to the Assigned Objects list or removing groups or NEs from the list. Click Next.
Step 6 Click Finish. The user whose properties were modified is listed in the MGM Users table.
8.3.4.5 Deleting a Cisco MGM User
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, select the user to be deleted.
Note A user cannot be deleted from the database until that user logs out. However, an active user session can be ended. See Ending an Active Cisco MGM User Session.
Step 3 Choose Edit > Delete (or click the Delete User tool).
Step 4 Click OK to remove the user from the database.
8.3.4.6 Viewing Logged In Cisco MGM Users
The Logged In Cisco MGM Users table allows you to view the users who are currently logged into the Cisco MGM application.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Logged In Cisco MGM Users. Table 8-12 describes the fields in the table.
8.3.4.7 Ending an Active Cisco MGM User Session
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, choose Administration > Logged In Cisco MGM Users.
Step 3 In the Logged In Cisco MGM Users table, select the user whose session will be ended and choose Administration > Log Out User (or click the Log Out User tool).
Step 4 Click Yes at the following prompt:
This operation will log out the selected Cisco MGM user. It will take approximately a minute and this Cisco MGM client will be unusable until then. Do you wish to continue?Wait while the Cisco MGM server logs out the selected Cisco MGM client. The Cisco MGM GUI is frozen for approximately 1 minute until the request is complete.
8.3.4.8 Using the Cisco MGM Locked Window
You can use the Cisco MGM Locked window to lock the current Cisco MGM session:
From the Domain Explorer window, choose:
File > Lock Cisco MGM Client
or
File > Lock Cisco MGM Users
Once the session is locked, the Domain Explorer disappears, and the Cisco MGM Locked window prompts you to enter your password to unlock the Cisco MGM session. You can attempt login up to the configured maximum login attempts to unlock the session. If the threshold is exceeded, Cisco MGM will terminate. Table 8-13 describes the field in the Cisco MGM Locked window.
Table 8-13 Field Descriptions for the Cisco MGM Locked Window
Field DescriptionPassword
Enter your password; then, click Unlock to unlock the Cisco MGM session.
8.3.4.9 Unlocking a User Account
By default, Cisco MGM allows users a maximum of five login attempts; the user account is locked after the fifth unsuccessful login attempt. The lockout duration is configurable and can be from 0 to 600 seconds or infinite.
Step 1 In the Domain Explorer window, choose Administration > Cisco MGM Users.
Step 2 In the Cisco MGM Users table, select the locked user.
Step 3 Choose Edit > Unlock (or click the Unlock User tool).
8.3.4.10 Changing Your User Password
Cisco MGM users can use the Change Password dialog box to change their Cisco MGM passwords at any time. The password change applies to the Cisco MGM user who is currently logged in. There is an enforced password change request when the default user logs in for the first time. If the user does not change the password, the Cisco MGM session is canceled.
Note The password complexity is configurable in the Control Panel > Security Properties pane.
Table 8-14 describes the fields in the Change Password dialog box.
Step 1 In the Domain Explorer window, choose Edit > Change Password.
Step 2 To change the Cisco MGM password:
a. In the Cisco MGM Password area, enter the current Cisco MGM password in the Old Password field.
b. Enter the new password in the New Password field. For Cisco MGM password constraints, see Table 8-14.
c. Confirm the new password.
d. Click OK.
Note Do not change the Cisco MGM passwords at the same time in the Change Password dialog box.
It is possible to set up the user account such that the change password function is disabled. See the description of the Password Change field in Creating a Cisco MGM User.
8.3.4.11 Setting User Preferences
Use the User Preferences dialog box to configure the Cisco MGM user interface.
Step 1 In the Domain Explorer window, choose Edit > User Preferences. The User Preferences dialog box opens. Table 8-15 describes the fields in the dialog box.
Step 2 After specifying the settings, check the Save current settings check box to preserve the current settings even after logging out. Users with the appropriate privileges can check the Save as the default user template check box to save the current settings as the default for new users who are added in the future. Current users who have not altered their default settings adopt the new default settings when they log out.
Step 3 Click OK to save the settings. After you save the selections, all subsequent views use the saved preferences.
8.3.4.12 Enabling or Disabling the Continuous Audible Alarm
You can enable or disable the continuous audible alarm, which can be enabled to sound when a specific alarm or event of a specific severity occurs on an NE or on the system.
Step 1 In the Domain Explorer window, choose Edit > User Preferences. The User Preferences dialog box opens.
Step 2 In the Event Notification tab > Play Audible Notification For area, check the Continuous Alarm For Dashboard Notifications check box.
Step 3 Click OK.
Step 4 To disable the continuous audible alarm, choose Fault > Stop Continuous Beep in the Domain Explorer window.
8.3.4.13 Configuring Cisco MGM Security Parameters
Use the Security Properties pane to configure Cisco MGM security parameters and password complexity rules. You can also specify usernames and passwords.
Note Passwords that are already in the system are not affected by modification(s) to the password complexity rules. The password complexity rules are checked when:
•A privileged user adds a new user to the system
•A privileged user modifies an existing user's password
•A user changes his or her own existing password
Step 1 In the Domain Explorer window, choose Administration > Control Panel.
Step 2 Click Security Properties and set the parameters described in Table 8-16.
Step 3 Click Save.
8.3.4.14 Sending Messages to Other Users
Use the Notify Users dialog box to type and send a message to all Cisco MGM users, or to all Cisco MGM users with the same user privileges. For example, you might want to use the Notify Users dialog box to alert all Cisco MGM users before shutting down the Cisco MGM server.
Table 8-17 describes the fields in the dialog box.
Step 1 In the Domain Explorer window, choose File > Notify Users. The Notify Users dialog box opens.
Step 2 In the Message Targets area, select the recipients of the message.
Step 3 Type the message in the Message area.
Step 4 To send the message to the specified recipients, click Send. To cancel the message and close the dialog box, click Cancel. To launch the online help for the Notify Users dialog box, click Help.
8.3.4.15 Viewing User Notification Messages
The User Notification dialog box pops up on your screen when another user sends a message to a certain user profile or to all Cisco MGM users, and you belong to one of those groups. Table 8-18 describes the fields in the dialog box.
8.4 How Do I Manage the Audit Log?
The Audit Log table contains information about significant events (user-initiated changes and activities) that occurred on the Cisco MGM server during a specified time period. By default, the Audit Log displays information about significant events that occurred during the last four hours. You can change the default time period in the User Preferences dialog box. Each record has a time stamp, record type, and message string.
There are two types of audit log available in Cisco MGM:
•Audit logs for the Diagnostic Center, Configuration Center, Statistics Reporting Tool and Chassis View. These audit logs are accessed directly from the log directory on the server at /opt/svplus/log.
•Audit logs for the other applications in Cisco MGM. Choose Administration > Audit Log to view these Audit logs.
Audit Log data can be filtered, see section Filtering Audit Log Data.
The Audit Log records the following runtime-affecting operations for monitoring purposes:
•Cisco MGM client logins, logouts, and security violations (including successful/unsuccessful client user logins and forced logouts)
•NE or group location changes in the Domain Explorer tree
•Domain Explorer group operations (add, delete, or modify a group)
•Changes in the Domain Explorer properties of an NE
•NE Service, PM Service, and Cisco MGM GateWay Service start or stop operations
•Cisco MGM user administration (add, delete, or modify user profile)
•Changes in:
–UI properties
–Security settings
–High availability settings
–Recovery settings
–Database configuration
–Error log configuration
–NE autobackup parameters
–NE service parameters
•Job or task cancellation in the Job Monitor table
•Manual memory backup
•Memory restore
•Software download
•OSS profile changes (CORBA)
•Cisco MGM GateWay/CORBA client logins/logouts
The following topics are covered:
8.4.1 Viewing the Audit Log
To view the Audit Log, choose Administration > Audit Log in the Domain Explorer window. Table 8-19 describes the fields in the Audit Log.
8.4.2 Filtering Audit Log Data
Use the Audit Log Filter dialog box to filter data according to criteria that you select and to display the results in the Audit Log table. To access the Audit Log Filter dialog box, in the Cisco MGM Audit Log window, choose File > Filter. Table 8-20 describes the fields in the filter dialog box.