Appendix
Below tables list different Ivanti Policy Secure messages which can be sent to SIEM systems for correlation, creating dashboards, reports and generating alerts.
Feature |
Category |
Sample Syslog |
|
---|---|---|---|
Authentication |
Primary authentication Success |
'<134>1 2019-07-01T00:47:59-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 00:47:59" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24326: Primary authentication successful for demouser System Local from 172.21.8.199"' |
Primary_Auth_Success
|
Authentication |
Primary authentication failed |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 02:34:01" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24327: Primary authentication failed for demouser/System Local from 172.21.8.199"' |
Primary_Auth_Failure
|
Authentication |
Secondary authentication success |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-18 02:48:51" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.24.57 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24326: Secondary authentication successful for demouser/System Local from 172.21.24.57" |
Secondary_Auth_Success
|
Authentication |
Secondary authentication failed |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-18 02:53:14" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.24.57 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24327: Secondary authentication failed for demouser/System Local from 172.21.24.57" |
Secondary_Auth_Failure
|
User login |
Pulse L3 login success |
'<134>1 2019-07-01T00:38:27-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 00:38:27" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="Users, Guest" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="Pulse-Secure/9.0.3.1071 (Macintosh 10_14) Pulse/9.0.3.1071" duration= msg="AUT24414: Agent login succeeded for demouser/Users from 172.21.8.199 with Pulse-Secure/9.0.3.1071 (Macintosh 10_14) Pulse/9.0.3.1071."' |
Pulse_L3_Auth
|
User login |
Pulse 802.1x login success |
'<134>1 2019-07-01T02:34:01-04:00 10.204.xx.xxx PulseSecure: - - - id=firewall time="2019-12-12 12:39:38" pri=6 fw=10.96.xx.xx vpn=ic user=demo_user realm="Users" roles="Users" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="Pulse-Secure/9.1.4.1655 (Windows 7) Pulse/9.1.4.1655" duration= msg="AUT24414: Agent login succeeded for demo_user/Users from 8c-70-5a-98-62-08 with Pulse-Secure/9.1.4.1655 (Windows 7) Pulse/9.1.4.1655." |
Pulse_L2_Auth
|
User login |
Agent-less login success |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 09:32:10" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="Users" proto=auth src=172.21.24.88 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:70.0) Gecko/20100101 Firefox/70.0" duration= msg="AUT31504: Login succeeded for demouser/Users (session:1c4e764b) from 172.21.24.88 with Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:70.0) Gecko/20100101 Firefox/70.0." |
Agentless_L3_Auth
|
User login |
native supplicant login |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-17 12:22:04" pri=6 fw=10.96.78.19 vpn=ic user=test1 realm="Users" roles="Remediation" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24414: Agent login succeeded for test1/Users from 00-21-cc-c5-c7-69 ." |
Native_Supplicant_L2_Auth
|
User login |
Login failure |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 02:34:01" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT23457: Login failed. Reason: No Roles"' |
Login_Failure_no_roles
|
User login |
Login failure |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 02:34:01" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT23457: Login failed using auth server System Local (Local Authentication). Reason: Failed"' |
Login_Auth_Failure
|
L2 Auth |
MAC Auth |
'<134>1 2019-07-01T02:10:58-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 02:10:58" pri=6 fw=10.204.57.142 vpn=ic user=System realm="" roles="" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24562: MAC address login succeeded for 00:21:86:f5:d6:ae Guest Wired from 00-21-86-f5-d6-ae." |
MAC_Auth
|
L2 Auth |
Radius Auth |
'<134>1 2019-07-01T02:10:58-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 02:10:58" pri=6 fw=10.204.57.142 vpn=ic user=00:21:86:f5:d6:ae realm="Guest Wired" roles="Guest Wired Restricted" proto= src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="EAM24805: RADIUS authentication accepted for 00:21:86:f5:d6:ae (realm \'Guest Wired\') from location-group \'Default\' and attributes are: NAS-IP-Address = 10.204.88.50,NAS-Port = 103,NAS-Port-Type = 15 "' |
Radius_Auth_Success
|
Logout |
User Logout |
'<134>1 2019-07-30T01:45:43-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-30 01:45:43" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="Users, Guest" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT22673: Logout from 172.21.8.199 (session:fd4a5bc4)"' |
User_Logout
|
Logout |
User Logout on receiving Radius Accounting STOP |
'<134>1 2019-07-30T01:45:43-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=demo_user realm="Users" roles="Users" proto= src=10.96.74.62 dst= dstname= type=vpn op= arg="" result= sent=rcvd= agent="" duration= msg="EAM24460: Received a RADIUS Accounting Stop request. Terminated session" |
User_Logout_on_Radius_Accounting_STOP
|
Logout |
User logout because of max session time out |
User_Logout_Max_Session_Timeout
|
|
Logout |
User idle timeout for routine system scan |
<134> 1 2019-06-12T17:07:19+05:30 10.204.58.32 PulseSecure: - - - id=firewall time="2019-06-12 17:07:19" pri=6 fw=10.204.58.32 vpn=ic user=demouser realm="Users" roles="remediate" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT20915: Session timed out for demouser/Users (session:f5dd3a33) due to inactivity (last access at 16:35:39 2019/06/12).Idle session identified during routine system scan." |
User_Logout_Session_Timeout_routine_scan
|
Logout |
User Idle Timeout after user request |
<134> 1 2019-06-12T17:07:19+05:30 10.204.58.32 PulseSecure: - - - id=firewall time="2019-06-12 17:07:19" pri=6 fw=10.204.58.32 vpn=ic user=demouser realm="Users" roles="remediate" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT20915: Session timed out for demouser/Users (session:f5dd3a33) due to inactivity (last access at 16:35:39 2019/06/12). Idle session identified after user request." |
User_Session_Timeout_user_request
|
L2 Access Control |
Radius Disconnect |
<134> 1 2019-06-12T17:07:19+05:30 10.204.58.32 PulseSecure: - - - id=firewall time="2019-12-17 12:22:29" pri=6 fw=10.96.78.19 vpn=ic user=test1 realm="Users" roles="Users, Remediation" proto= src=0.0.0.0 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="COA24753: Session Deletion Disconnect Message sent to RADIUS Client Cisco 3850 for agent at 00-21-cc-c5-c7-69 has succeeded." |
Radius_COA_Success
|
L2 Access Control |
Radius COA |
<134> 1 2019-06-12T17:07:19+05:30 10.204.58.32 PulseSecure: - - - id=firewall time="2019-12-17 12:22:29" pri=6 fw=10.96.78.19 vpn=ic user=test1 realm="Users" roles="Users, Remediation" proto= src=0.0.0.0 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="COA31277: VLAN/RADIUS Attribute Change of Authorization Message sent to RADIUS Client C2960X-VLAN60 for agent at 00-21-cc-5d-d9-0f has succeeded."' |
Radius_COA_Success
|
Host Checker |
Host Checker policy success |
''<134>1 2019-07-01T00:58:00-04:00 10.204.xx.xxx PulseSecure: - - - id=firewall time="2019-07-01 00:58:00" pri=6 fw=10.204.xx.xxx vpn=ic user=demouser realm="Users" roles="Guest" proto=auth src=172.21.x.xxx dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24803: Host Checker policy \'firewall policy\' passed on host \'172.xx.x.xxx\' address \'ac-bc-32-77-44-27\' for user \'demouser\' <134>1 2019-07-01T00:48:00-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 00:48:00" pri=6 fw=10.204.xx.xxx vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.x.xxx dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24804: Host Checker policy \'firewall policy\' failed on host \'172.xx.xx.xx\' address \'ac-bc-32-77-44-27\' for user \'demouser\' reason \'Rule-firewall:Mac OS X Builtin Firewall 10.14.5 does not comply with policy. Compliance requires firewall to be turned on.\'. |
HC_Pass
|
Host Checker |
Host Checker policy failure |
'<134>1 2019-07-01T00:48:00-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-01 00:48:00" pri=6 fw=10.204.57.142 vpn=ic user=demouser realm="Users" roles="" proto=auth src=172.21.8.199 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT24804: Host Checker policy \'firewall policy\' failed on host \'172.21.8.199\' address \'ac-bc-32-77-44-27\' for user \'demouser\' reason \'Rule-firewall:Mac OS X Builtin Firewall 10.14.5 does not comply with policy. Compliance requires firewall to be turned on.\'."' |
HC_Failure
|
Role Change |
Role Change |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-17 12:31:25" pri=6 fw=10.96.78.19 vpn=ic user=test1 realm="Users" roles="Users, Remediation" proto=auth src=10.204.90.68 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT23077: Roles for user test1 on host 10.204.90.68 changed from <Users,Remediation> to <Remediation>." |
role_change
|
Session Bridging |
Browser session bridge |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-17 12:22:27" pri=6 fw=10.96.78.19 vpn=ic user=test1 realm="Users" roles="Remediation" proto=auth src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT31498: Browser connection bridged for test1/Users (session:06dc44e3) from 10.204.90.68." |
agentless_session_bridge
|
IP Assignment |
IP assignment because of Radius Accounting START |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:34:11" pri=6 fw=10.96.78.19 vpn=ic user=demo_user realm="Users" roles="Users" proto= src=10.96.74.62 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="SBR31642: User demo_user has been assigned IP address 10.96.74.62" |
Accounting_START_IP_Address_Assignment |
IP Release |
IP release because of Radius Accounting STOP |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=demo_user realm="Users" roles="Users" proto=auth src=10.96.74.62 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="AUT31643: IP Address 10.96.74.62 has been released for the user demo_user" |
Accounting_STOP_IP_Address_Release |
SSH Enforcement |
SSH ACL Enforcement |
'<134>1 2019-07-29T15:42:59+05:30 ppsqa1 PulseSecure: - - - id=firewall time="2019-07-29 15:42:59" pri=6 fw=10.96.76.4 vpn=ic user=System realm="" roles="" proto= src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="EAM24460: Successfully created configuration for applying ACL \'PPS-3COM-Default-ACL\' on interface Ethernet1/0/9 of Switch 10.204.88.17"' |
SSH_ACL_Enforcement
|
SSH Enforcement |
SSH VLAN Enforcement |
'<134>1 2019-07-30T12:36:41+05:30 ppsqa1 PulseSecure: - - - id=firewall time="2019-07-30 12:36:41" pri=6 fw=10.96.76.4 vpn=ic user=System realm="" roles="" proto= src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="EAM24460: Successfully created configuration for applying vlanId = \'65\' on interface Ethernet1/0/9 of Switch 10.204.88.17"' |
SSH_VLAN_Enforcement
|
SSH Enforcement |
SNMP MAC Auth session end |
'<134>1 2019-07-29T15:42:56+05:30 ppsqa1 PulseSecure: - - - id=firewall time="2019-07-29 15:42:56" pri=6 fw=10.96.76.4 vpn=ic user=00:21:cc:da:a8:d3 realm="Guest Wired" roles="" proto= src=127.0.0.1 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="EAM24460: Terminated SNMP based MAC Auth Session"' |
SNMP_MAC_Auth_Session_End
|
Admission Control Action |
Change of role |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=demo_user realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31554: Changed role for endpoint: 10.204.90.72( 00-21-CC-5D-D9-0F ) to Guest"' |
Admission_Control_Action_Role_Change
|
Admission Control Action |
Quarantine Endpoint |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31555: Endpoint with MAC address: 00-21-CC-5D-D9-0F has been quarantined"' |
Admission_Control_Action_Quarantine_Endpoint
|
Admission Control Action |
Quarantine User |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31555: User: demouser has been quarantined"' |
Admission_Control_Action_Quarantine_User
|
Admission Control Action |
Terminate User Session |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31553: User: demouser with session ID: sid123456 is being terminated"' |
Admission_Control_Action_Terminate_Session
|
Admission Control Action |
Disable User |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31552: User: demouser with session ID: sid123456 has been disabled"' |
Admission_Control_Action_Disable_User
|
Admission Control Action |
|
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31547: Policy: policy1 Action: Ignore for sid: sid1234567890 |
Admission_Control_Action_Ignore
|
Admission Control Action |
Update role failure |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-11 11:36:03" pri=6 fw=10.96.78.19 vpn=ic user=00-21-CC-5D-D9-0F realm="Users" roles="Guest" proto= src=10.204.90.72 dst= dstname= type=vpn op= arg="" result= sent= rcvd= agent="" duration= msg="INT31546: Failed to update role for sid: sid1234567890"' |
Admission_Control_Action_Role_Update_Failure
|
Below Profiler logs are captured in Ivanti Policy Secure Events logs and same can be used to show the number of discovered devices.
Feature |
Sub-Feature |
Sample Syslog |
Event Type |
---|---|---|---|
Profiler |
Device OS Classification |
<134>1 2019-07-23T04:52:10-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-23 04:52:10" pri=6 fw=10.204.57.142 vpn=ic user=System realm="" roles="" type=mgmt proto= src=127.0.0.1 dst= dstname= sent= rcvd= msg="PRO31368: Device (ac:1f:6b:62:28:bb) is classified as Linux." |
Device_Classification
|
Profiler |
Device profile Change |
<134>1 2019-07-23T04:53:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-23 04:53:01" pri=6 fw=10.204.57.142 vpn=ic user=System realm="" roles="" type=mgmt proto= src=127.0.0.1 dst= dstname= sent= rcvd= msg="PRO31369: Device (00:50:56:8e:dc:16) has changed profile from category Linux to Routers and APs." |
Profile_Change
|
Profiler |
Device attribute update (from Ivanti Policy Secure session) |
<134>1 2019-07-23T03:35:52-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-07-23 03:35:52" pri=6 fw=10.204.57.142 vpn=ic user=System realm="" roles="" type=mgmt proto= src=127.0.0.1 dst= dstname= sent= rcvd= msg="PRO31459: Device(ac-bc-32-77-44-27)\'s attributes got updated from (first_seen = {2019-07-23 07:12:20.531374+00:00} previous_category = {} os = {Macintosh 10_14} category = {Macintosh} ip = {172.21.8.199} previous_os = {} last_seen = {2019-07-23 07:35:44.369781+00:00} macaddr = {ac:bc:32:77:44:27} manufacturer = {Apple, Inc.} profiler_name = {profiler} status = {approved} ) to (first_seen = {2019-07-23} previous_category = {} os = {Macintosh 10_14} category = {Macintosh} ip = {172.21.8.199} previous_os = {} last_seen = {2019-07-23} macaddr = {ac:bc:32:77:44:27} manufacturer = {Apple, Inc.} profiler_name = {profiler} status = {approved} )." |
Device_Attribute_Update
|
Concurrent Users |
Number of concurrent users |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 16:00:44" pri=6 fw=10.96.7.66 vpn=n-166 user=System realm="" roles="" type=mgmt proto= src=127.0.0.1 dst= dstname= sent= rcvd= msg="STS20641: Number of concurrent users logged in to the device: 3" |
Number_Of_CC_Users
|
Below Profiler logs are captured in Ivanti Policy Secure Events logs and same can be used to show the number of discovered devices, device information by OS/Category, the number devices with profile change etc
Feature |
Category |
Sample Syslog |
Event Type |
---|---|---|---|
Third Party Device management |
Enforcer addition |
<134>1 2019-08-08T02:01:21-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-08-08 02:01:21" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM23472: Added Enforcer \'PAN firewall\'" |
New_Enforcer
|
|
Enforcer removal |
<134>1 2019-08-08T02:09:28-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-08-08 02:09:28" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM23473: Deleted Enforcer \'PAN firewall\'"' |
Enforcer_Deleted
|
|
Radius Client addition |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 03:43:28" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM24357: Added RADIUS Client 'cisco'" |
New_Radius_Client
|
|
Radius Client Removal |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 03:51:46" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM24358: Deleted RADIUS Client 'cisco'" |
Radius_Client_Delete
|
|
Admission Control Client addition |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 04:04:05" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM31536: Admission Control Client added: 'Juniper_SDSN'" |
New_Admission_Control_Client
|
|
Admission Control Client removal |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 04:06:34" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM31538: Admission Control Client deleted: 'Juniper_SDSN'" |
Admission_Control_Client_Delete
|
|
SNMP Switch addition |
<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 06:08:34" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM31358: Added SNMP switch 'Cisco'" |
New_SNMP_Switch
|
|
SNMP Switch removal |
'<134>1 2019-07-01T02:34:01-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-12-19 09:04:03" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="ADM31359: Deleted SNMP Switch 'Cisco'" |
SNMP_Switch_Delete
|
License |
License Added |
<134>1 2019-08-08T02:18:42-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-08-08 02:18:42" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="LIC10201: License for \'Pulse Policy Secure License 100 Concurrent Sessions - Subscription 1 Year\' - \'kernel ice soccer holiday camel integrity equator square bracelet world falcon\' installed" |
License_Added
|
License |
License Removed |
<134>1 2019-08-08T02:18:33-04:00 10.204.57.142 PulseSecure: - - - id=firewall time="2019-08-08 02:18:33" pri=6 fw=10.204.57.142 vpn=ic user=admin realm="Admin Users" roles=".Administrators" type=mgmt msg="LIC10202: License for \'Pulse Policy Secure License 100 Concurrent Sessions - Subscription 1 Year\' - \'kernel ice soccer holiday camel integrity equator square bracelet world falcon\' removed" |
License_Removed
|