02-24-2010 09:23 AM - edited 03-10-2019 04:58 PM
Hello,
We use RANCID to monitor changes to all our Cisco gear. Once an hour RANCID does a diff on the last running-config. If it detects a change, it notifies me of the changes on the router/switch. This works great, but it does not record WHO made the changes.
So I am looking for a way to log to syslog any commands issued by a particular user. This can be done correct?
Thanks,
Pedro
02-24-2010 10:58 AM
You can use AAA accounting for it.
I hope it helps.
PK
02-24-2010 11:00 AM
What I am not sure of is if you can do aaa acounting to syslog and if you can do it on a per user basis.
02-24-2010 11:15 AM
I doubt you can do accounting to syslog (send commands).
PK
02-25-2010 03:41 PM
If you are using IOS 12.4 or higher, you can use the following commands:
archive
log config
hidekeys
It will send whatever changes and whoever changes the configs to syslog.
I myself prefer AAA accounting but the above method will work just as well.
03-01-2010 06:18 AM
Thanks for answering my post!
IOS 12.4 or higher? Is that a typo? Isnt 12.2 the latest? I tried these commands on one of my switches and I still dont see anything in syslog.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide