TACACS+ Account Logs
the kron pam tacacs+ access manager is used for tacacs+ authentication for network devices policy enforcement can also be applied to network devices that use the kron pam tacacs+ access manager all commands executed during the session can be viewed in the tacacs account log menu, along with the following information username, host ip used to connect, command run, policy enforcement, user privilege level, host port type, log detail, client ip, log time, and instance name to access the tacacs account logs navigate to logging > tacacs account log fill in the fields to filter and click the search button the more button can add extra filtering columns to the screen when the button is clicked, more than one value can be selected from the popup the selected columns will be added to the screen in order and filtering can be done according to the values entered by the user