How-To Guides
...
Integrate with SIEM Systems
Log Packets Explanations

Sapm_New_User

1min

This log file contains new users added to an SAMP account. The new users on the target devices are logged in the Kron PAM as a SAPM New User Log. The table below shows the information sent with this log.

Time

Time of the New User Found log.

deviceIp

IP of the device used to create the new user.

deviceHostname

Name of the device used to create the new user.

usedLoginUsername

Username of the user that created the new user.

Status

Shows if there is a new user.

newUser

Name of the new user.

Log

Activity status is shown if there is an error during the process.

InstanceName

Instance by which the new user was created.

permissions

Permission assigned to the newly created user.

sapmAccount

SAPM Account, if the newly created user has been added to an SAPM Account.



Syslog Version | Syslog Timestamp | Syslog Hostname | Syslog App Name | Syslog Process ID | Syslog Log Message

1 2021-04-01T10:52:52.384Z d-scon01 SyslogSenderForSapm_New_User - - - CEF:0|KRONTECH|singleconnect|2.20.0|100|Sapm_New_User|10|SapmNewUsersLog{, time=2021-04-01 12:17:07.943, deviceIp\='83.91.179.22', deviceHostname='Linux-Test', usedLoginUsername='pam-test11',status\=FOUND, newUser\='sapmtest', log='null', instanceName='d-scon01', permissions=null, sapmAccount=null}