Auth Log
This log contains logs of any authentication attempt made by the user on Kron PAM. The packets are sent to the server in the following format:
dbId | Database ID of the authentication log in the PAM Database |
|---|---|
id | Specific ID of the log in the PAM Database |
time | Time trying to authenticate |
event | The event that takes on the following values: 0: LOGIN_SUCCESS 1: LOGIN_FAILURE 2: LOGOUT 3: LOGIN_TOKEN_PROVIDED 4: AUTH_CHALLENGE |
eventSource | Event source for the authentication log. It can take on the following values: ui, api, Tacacs, global-user-auth, kcore-rest-api,scproxy-ssh-key, scproxy |
clientIp | The source IP that sends the auth request |
tenantId | Tenant, the auth request has started |
Params | Whether the Authentication is a success or a failure, the related parameters are sometimes noted in this field. Ex:” Active Directory Error 52e: Invalid Credentials”, “Global Username: root” |
nasIp | The IP address of the target device |
nasHostname | The IP hostname of the target device |
username | The username entered in the interface |
externalDirectorySource | If the user is an LDAP/AD user, this field is filled; The LDAP source name in KRON PAM |
instanceName | Kron PAM instance by which the auth request is started |
deviceGroupNames | Group names of the target device |
Example:
Authentication log with admin user: