The audit messages in this section are from the Cryptographic Security Platform Vault for KMIP.
In the table below, we list many of the audit messages and show:
- Whether an Alert is also generated.
- The severity (L=Low, M=Medium, H=High).
- What the resolution is if any action should be taken.
In the Message column, a value in braces, such as
{user_name}, represents a placeholder that is replaced with an actual value. For example, in the following message:'{user_name}' created the policy '{policy_name}'The actual message will be displayed with the name of the user and policy, for example:
Fred created the policy 'Default_Policy'
Msg ID | Message | Severity | Alert? | Category |
|---|---|---|---|---|
300 | {user_name} created the policy '{policy_name}' | M | false | KMIP |
301 | {user_name} updated the policy '{policy_name}'. New policy version is {policy_version}. | M | false | KMIP |
302 | {user_name} deleted the policy '{policy_name}' | M | false | KMIP |
303 | {user_name} changed the current version of the policy '{policy_name}'. Current policy version is {policy_version}. | M | false | KMIP |
400 | KMIP Client Certificate '{name}' created | H | false | KMIP |
401 | KMIP Client Certificate '{name}' created using Certificate Signing Request | H | false | KMIP |
402 | KMIP Client Certificate '{name}' deleted | H | false | KMIP |
403 | KMIP Client Certificate '{name}' created using uploaded Certificate | H | false | KMIP |
500 | User '{user_name}' logged in successfully. | H | false | KMIP |
501 | Active Directory login for {username} succeeded, but KMIP portal failed to retrieve information about the user. The user might not belong to the Active Directory Domain {domain_name} or user/group Base DN in Active Directory configuration might be wrong. Please contact KMIP Administrator to validate the Active Directory setup. | H | false | KMIP |
502 | Login failure for Active Directory user {username} | H | false | KMIP |
503 | User '{user_name}' logged in successfully using Personal Access Token {token_name}. | H | false | KMIP |
504 | {user_name} enabled authentication inheritance | M | false | KMIP |
505 | Authentication settings for inheriting vault '{vault_name}' were '{action}' by System Administrator | M | false | KMIP |
600 | {user_name} updated AD Setting '{ad_setting_name}' | M | false | KMIP |
601 | {user_name} changed AD Domain from '{old_ad_setting_name}' to '{ad_setting_name}' | M | false | KMIP |
602 | {user_name} added AD Setting '{ad_setting_name}' | M | false | KMIP |
700 | KMIP Request - Operation: {op}, Object: {obj}, UUID: {uuid} from KMIP Client - {user} (IP: {client_ip}) | H | false | KMIP |
701 | KMIP Response - Operation: {op}, Object: {obj}, UUID: {uuid}, Result: {result}, from KMIP Client - {user} (IP: {client_ip}) | H | false | KMIP |
702 | KMIP Action Request from WebGUI. Action: Revoke, UUID: {uuid}. Revocation Code: {revcode}, Revocation message: {revmsg}, Result: {result} (IP: {client_ip}) | H | false | KMIP |
703 | KMIP Action Response from WebGUI. Action: {op}, UUID: {uuid}, Result: {result} (IP: {client_ip}) | H | false | KMIP |
800 | {user_name} updated KMIP '{kmip_name}' settings. 'degraded mode availability' {degraded_mode}. 'OIDC authentication' {oidc}. 'audit alert distribution list' {audit_alert_dl}. 'alert read count' {alert_read_count}. 'email notify alerts' {email_notify_alerts}. | M | false | KMIP |
801 | {user_name} updated KMIP '{kmip_name}' settings of authentication method to AD based authentication with Active Directory domain '{ad_domain}' | M | false | KMIP |
802 | {user_name} updated KCM settings for KMIP '{kmip_name}' with KCM IP '{kcm_ip}'. | M | false | KMIP |
803 | {user_name} updated KMIP '{kmip_name}' settings of authentication method to OIDC based authentication | M | false | KMIP |
900 | {username} updated KEK Setting | M | false | KMIP |
901 | {username} enabled KMIP KEK wrapping | M | false | KMIP |
902 | {username} disabled KMIP KEK wrapping | M | false | KMIP |
1000 | Successfully completed rekey of KMIP objects | L | false | KMIP |
1001 | Successfully completed decryption of KMIP objects | L | false | KMIP |
1002 | Successfully started rekey of KMIP objects | L | false | KMIP |
1100 | Successfully reset KMIP vault {tenant} | L | false | KMIP |
1200 | {user_name} created the user '{name}' | M | false | KMIP |
1201 | {user_name} deleted the user '{name}' | M | false | KMIP |
1202 | {user_name} updated the user '{name}' | M | false | KMIP |
1203 | Account {user_name} was locked for 5 minutes due to repeated login failures | H | false | KMIP |
1204 | Account {user_name} was disabled due to repeated login failures | H | false | KMIP |
1205 | Login failure for Local user {username} from {client_ip}. Reason: {reason} | H | false | KMIP |
1206 | Password successfully updated for user: {username} | H | false | KMIP |
1207 | Account {user_name} enabled Two-Factor Authentication | L | false | KMIP |
1208 | Account {user_name} disabled Two-Factor Authentication | L | false | KMIP |
1209 | {user_name} updated the local user password policy | M | false | KMIP |
1210 | {user_name} enforced Two-Factor Authentication | M | false | KMIP |
1211 | {user_name} removed enforcement of Two-Factor Authentication | M | false | KMIP |
1300 | {user_name} created Personal Access Token {token_name} | M | false | KMIP |
1301 | {user_name} {update_info} Personal Access Token {token_name} | M | false | KMIP |
1302 | {user_name} deleted Personal Access Token {token_name} | M | false | KMIP |
1400 | {user_name} created OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1401 | {user_name} failed to create OIDC user {oidc_user_email} | M | false | KMIP |
1402 | {user_name} updated OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1403 | {user_name} failed to update OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1404 | {user_name} deleted OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1405 | {user_name} failed to delete OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1406 | {user_name} created registration link for OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1407 | {user_name} failed to create registration link for OIDC user {oidc_user_email}: {oidc_user_guid} | M | false | KMIP |
1408 | Login failure for OIDC user {username} from {client_ip}. Reason: {reason} | M | false | KMIP |
1500 | {user_name} created SCIM Token {token_id} expiring on {expiry_date} | M | false | KMIP |
1501 | User {oidc_user_name} ({oidc_user_email}: {oidc_user_guid}) deleted by SCIM | M | false | KMIP |
1502 | User {oidc_user_name} ({oidc_user_email}: {oidc_user_guid}) created by SCIM and added to policy {policy_name} | M | false | KMIP |
1503 | User ({oidc_user_email}: {oidc_user_guid}) updated by SCIM from '{old_name}' to '{new_name}' | M | false | KMIP |
1504 | {user_name} deleted SCIM Token | M | false | KMIP |
1600 | KMIP client certificate '{cert_name}' has expired. KMIP clients using this certificate will no longer be able to access the KMIP server. Please create a new certificate and update the KMIP clients. | H | true | KMIP |
1601 | KMIP client certificate '{cert_name}' will expire in {days} days, {hours} hours and {minutes} minutes. Please create a new certificate and update the KMIP clients before it expires. | H | true | KMIP |
1602 | {user_name} updated OIDC configuration on vault '{vault_name}' | H | true | KMIP |
1603 | {user_name} updated OIDC CA certificate for vault '{vault_name}' | H | true | KMIP |