Skip to main content
Skip table of contents

Syslog - CA Privileged Access Manager (PAM)

Device Details

Device NameSyslog – CA Privileged Access Manager
VendorCA Technologies (BROADCOM)
Device TypeDevice and Password Access Control
Supported Model Name/NumberPrivileged Credential Vault
Supported Software VersionN/A
Collection MethodSyslog
Configurable Log OutputNo
Log Source TypeSyslog – CA Privileged Access Manager
Log Processing PolicyLogRhythm Default
ExceptionsN/A
Additional Information

https://techdocs.broadcom.com/us/en/symantec-security-software/identity-security/identity-management-and-governance-connectors/1-0/connectors/ca-connectors/ca-privileged-access-manager.html

Prerequisites

To access CA Privileged Access Manager, you need one of the following Web browsers:

  • Microsoft Internet Explorer 11 or higher
  • Mozilla Firefox
  • Apple Safari
  • Google Chrome


Supported Log Messages

 (List of LR Tags used to parse the log information for each message type)

TypeProduct VersionSupported Schema Fields

Catch All

All

<severity>

Cloakware Metric Messages

All

<severity> ,<login>, <account>, <object>, <status>, <recipient>, <group>, <subject>, <sname>, <dname>, <sip>

Gatekeeper Syslog Messages

All

<severity> ,<processid>, <sip> ,<snatip> ,<login> ,<action> ,<dip> ,<sname> ,<group> , <sport> , <protname> ,<subject> ,<useragent>, <policy>, <object>, <vendorinfo>, <dport> , <kilobytes> ,<url>,<dname>, <domainorigin>, <tag1>

Gksyslog MessagesAll<severity> ,<processid>,<login>, <useragent>, <domainorigin>, <sname>, <action>, <subject>
Logwatch Process MessagesAll<severity>, <processid>, <subject>, <action>

Metric Login Messages

All

<severity> ,<action>, <login>, <sip>, <sname>

Metric Schedule Job Messages

All

<severity> ,<action>, <subject>, <account>, <command>, <login>, <sip>, <sname>

Metric Update Password Messages

All

<severity> ,<action>, <login>, <object>, <account>, <minutes>

Metric View Password Messages

All

<severity> ,<action>, <login>, <object>, <reason>, <dname>, <command>, <account>, <sip>, <sname>,<responsecode>

Password Expire View Request MessagesAll<severity> ,<action>, <processid>, <login>, <responsecode>, <account>, <sip>, <sname>

X-suite Messages

All

<severity> ,<processid>, <sip> ,<snatip> ,<login>, <tag1>, <dip>, <sname>, <subject>, <dport>, <protname>, <object>, <status>, <minutes>

Revision History

KB Version

Log Type

Change Type

Details

KB 7.1.598.0

Syslog

DocumentationUpdated existing device documentation
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.