How-To Guides
...
Integrate with SIEM Systems
Log Packets Explanations

EventLog

2min

EventLog keeps all activities that users produce on the Kron PAM WebGUI. You can view the same logs on the Logging > Activity Logs page of the WebGUI.

Event types are labeled as “type=xxxxxxx”.

The table below shows the information sent with this log.

Type

Event type generated by the user.

userName

The username that created the event on Kron PAM.

clientlp

Kron PAM Host IP.

instanceName

Instance by which the event was created.

sourceld

ID of the event source.

Time

The exact time when the event was created

Params

Represents the parameter name of the created event.



Syslog Version | Syslog Timestamp | Syslog Hostname | Syslog App Name | Syslog Process ID | Syslog Log Message

1 2021-04-01T10:52:52.384Z d-scon01 SyslogSenderForEventLog - - - CEF:0|KRONTECH|singleconnect|2.20.0|100|EventLog|10|{type\='/system/config/save', userName\='admin', clientIp\='62.242.222.157', instanceName\='d-scon01',sourceId\='-100006', time\=2021-01-26 11:58:20.685, params\='{parameterValue\=change_it, parameterName\=mail.userName}'}

Syslog Version | Syslog Timestamp | Syslog Hostname | Syslog App Name | Syslog Process ID | Syslog Log Message

1 2021-04-01T10:52:52.384Z d-scon01 SyslogSenderForEventLog - - - CEF:0|KRONTECH|singleconnect|2.20.0|100|EventLog|10|{type\='/device/discovered' , userName\='admin', clientIp\='62.242.222.62', instanceName\='d-scon01', sourceId\='39e099b5-5824-4e31-bec2-f92350afee61', time\=2021-02-23 13:40:29.326, params\='{deviceName\=Windows-Test, managementIp\=83.91.179.21}'}