The audit messages in this section are from the Cryptographic Security Platform Vault for KMIP.

In the table below, we list many of the audit messages and show:

  • Whether an Alert is also generated.
  • The severity (L=Low, M=Medium, H=High).
  • What the resolution is if any action should be taken.
  • In the Message column, a value in braces, such as {user_name}, represents a placeholder that is replaced with an actual value. For example, in the following message:

    '{user_name}' created the policy '{policy_name}'

    The actual message will be displayed with the name of the user and policy, for example:

    Fred created the policy 'Default_Policy'


Msg ID

Message

Severity

Alert?

Category

300

{user_name} created the policy '{policy_name}'

M

false

KMIP

301

{user_name} updated the policy '{policy_name}'. New policy version is {policy_version}.

M

false

KMIP

302

{user_name} deleted the policy '{policy_name}'

M

false

KMIP

303

{user_name} changed the current version of the policy '{policy_name}'. Current policy version is {policy_version}.

M

false

KMIP

400

KMIP Client Certificate '{name}' created

H

false

KMIP

401

KMIP Client Certificate '{name}' created using Certificate Signing Request

H

false

KMIP

402

KMIP Client Certificate '{name}' deleted

H

false

KMIP

403

KMIP Client Certificate '{name}' created using uploaded Certificate

H

false

KMIP

500

User '{user_name}' logged in successfully.

H

false

KMIP

501

Active Directory login for {username} succeeded, but KMIP portal failed to retrieve information about the user. The user might not belong to the Active Directory Domain {domain_name} or user/group Base DN in Active Directory configuration might be wrong. Please contact KMIP Administrator to validate the Active Directory setup.

H

false

KMIP

502

Login failure for Active Directory user {username}

H

false

KMIP

503

User '{user_name}' logged in successfully using Personal Access Token {token_name}.

H

false

KMIP

504

{user_name} enabled authentication inheritance

M

false

KMIP

505

Authentication settings for inheriting vault '{vault_name}' were '{action}' by System Administrator

M

false

KMIP

600

{user_name} updated AD Setting '{ad_setting_name}'

M

false

KMIP

601

{user_name} changed AD Domain from '{old_ad_setting_name}' to '{ad_setting_name}'

M

false

KMIP

602

{user_name} added AD Setting '{ad_setting_name}'

M

false

KMIP

700

KMIP Request - Operation: {op}, Object: {obj}, UUID: {uuid} from KMIP Client - {user} (IP: {client_ip})

H

false

KMIP

701

KMIP Response - Operation: {op}, Object: {obj}, UUID: {uuid}, Result: {result}, from KMIP Client - {user} (IP: {client_ip})

H

false

KMIP

702

KMIP Action Request from WebGUI. Action: Revoke, UUID: {uuid}. Revocation Code: {revcode}, Revocation message: {revmsg}, Result: {result} (IP: {client_ip})

H

false

KMIP

703

KMIP Action Response from WebGUI. Action: {op}, UUID: {uuid}, Result: {result} (IP: {client_ip})

H

false

KMIP

800

{user_name} updated KMIP '{kmip_name}' settings. 'degraded mode availability' {degraded_mode}. 'OIDC authentication' {oidc}. 'audit alert distribution list' {audit_alert_dl}. 'alert read count' {alert_read_count}. 'email notify alerts' {email_notify_alerts}.

M

false

KMIP

801

{user_name} updated KMIP '{kmip_name}' settings of authentication method to AD based authentication with Active Directory domain '{ad_domain}'

M

false

KMIP

802

{user_name} updated KCM settings for KMIP '{kmip_name}' with KCM IP '{kcm_ip}'.

M

false

KMIP

803

{user_name} updated KMIP '{kmip_name}' settings of authentication method to OIDC based authentication

M

false

KMIP

900

{username} updated KEK Setting

M

false

KMIP

901

{username} enabled KMIP KEK wrapping

M

false

KMIP

902

{username} disabled KMIP KEK wrapping

M

false

KMIP

1000

Successfully completed rekey of KMIP objects

L

false

KMIP

1001

Successfully completed decryption of KMIP objects

L

false

KMIP

1002

Successfully started rekey of KMIP objects

L

false

KMIP

1100

Successfully reset KMIP vault {tenant}

L

false

KMIP

1200

{user_name} created the user '{name}'

M

false

KMIP

1201

{user_name} deleted the user '{name}'

M

false

KMIP

1202

{user_name} updated the user '{name}'

M

false

KMIP

1203

Account {user_name} was locked for 5 minutes due to repeated login failures

H

false

KMIP

1204

Account {user_name} was disabled due to repeated login failures

H

false

KMIP

1205

Login failure for Local user {username} from {client_ip}. Reason: {reason}

H

false

KMIP

1206

Password successfully updated for user: {username}

H

false

KMIP

1207

Account {user_name} enabled Two-Factor Authentication

L

false

KMIP

1208

Account {user_name} disabled Two-Factor Authentication

L

false

KMIP

1209

{user_name} updated the local user password policy

M

false

KMIP

1210

{user_name} enforced Two-Factor Authentication

M

false

KMIP

1211

{user_name} removed enforcement of Two-Factor Authentication

M

false

KMIP

1300

{user_name} created Personal Access Token {token_name}

M

false

KMIP

1301

{user_name} {update_info} Personal Access Token {token_name}

M

false

KMIP

1302

{user_name} deleted Personal Access Token {token_name}

M

false

KMIP

1400

{user_name} created OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1401

{user_name} failed to create OIDC user {oidc_user_email}

M

false

KMIP

1402

{user_name} updated OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1403

{user_name} failed to update OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1404

{user_name} deleted OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1405

{user_name} failed to delete OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1406

{user_name} created registration link for OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1407

{user_name} failed to create registration link for OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1408

Login failure for OIDC user {username} from {client_ip}. Reason: {reason}

M

false

KMIP

1500

{user_name} created SCIM Token {token_id} expiring on {expiry_date}

M

false

KMIP

1501

User {oidc_user_name} ({oidc_user_email}: {oidc_user_guid}) deleted by SCIM

M

false

KMIP

1502

User {oidc_user_name} ({oidc_user_email}: {oidc_user_guid}) created by SCIM and added to policy {policy_name}

M

false

KMIP

1503

User ({oidc_user_email}: {oidc_user_guid}) updated by SCIM from '{old_name}' to '{new_name}'

M

false

KMIP

1504

{user_name} deleted SCIM Token

M

false

KMIP

1600

KMIP client certificate '{cert_name}' has expired. KMIP clients using this certificate will no longer be able to access the KMIP server. Please create a new certificate and update the KMIP clients.

H

true

KMIP

1601

KMIP client certificate '{cert_name}' will expire in {days} days, {hours} hours and {minutes} minutes. Please create a new certificate and update the KMIP clients before it expires.

H

true

KMIP

1602

{user_name} updated OIDC configuration on vault '{vault_name}'

H

true

KMIP

1603

{user_name} updated OIDC CA certificate for vault '{vault_name}'

H

true

KMIP