How-To Guides
...
Log Formats
Auth Log
1 min
this log contains logs of any authentication attempt made by the user on kron pam the packets are sent to the server in the following format dbid database id of the authentication log in the pam database id specific id of the log in the pam database time time trying to authenticate event the event that takes on the following values 0 login success 1 login failure 2 logout 3 login token provided 4 auth challenge eventsource event source for the authentication log it can take on the following values ui, api, tacacs, global user auth, kcore rest api,scproxy ssh key, scproxy clientip the source ip that sends the auth request tenantid tenant, the auth request has started params whether the authentication is a success or a failure, the related parameters are sometimes noted in this field ex ” active directory error 52e invalid credentials”, “global username root” nasip the ip address of the target device nashostname the ip hostname of the target device username the username entered in the interface externaldirectorysource if the user is an ldap/ad user, this field is filled; the ldap source name in kron pam instancename kron pam instance by which the auth request is started devicegroupnames group names of the target device example authentication log with admin user {dbid=1877583, id='be4c9d57 8111 432e b98c f56a3be8e3b5', time=2025 04 24 12 33 51 489, event=0, eventsource='global user auth', clientip='10 0 1 1', tenantid='krontech', params='global username pamuser', nasip='10 10 10 10', nashostname='10 10 10 10', username='admin', externaldirectorysource=null, instancename='kronpam', devicegroupnames='linux device'}