Skip to main content
Skip table of contents

TACACS Diagnostics

Vendor Documentation

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
pri_numN/AN/A
timeN/AN/A
IP address/hostnameN/AN/A
cat_nameN/A<vendorinfo>
msg_idN/AN/A
total_segN/AN/A
seg_numN/AN/A
timestampN/AN/A
sequence_numN/AN/A
msg_codeN/A<vmid>
<tag1>
msg_sev<severity><severity>
msg_class<process><subject> 
msg_text<status>
<tag1>
<action> 
ConfigVersionId<version>N/A
Device IP Address<dip><sip>
Device Port<dport><sport>
CmdSetN/AN/A
MatchedCommandSetN/AN/A
MatchedRuleN/AN/A
MajorVersionN/AN/A
MinorVersionN/AN/A
TypeN/A<objecttype>
Sequence-NumberN/AN/A
Header-FlagsN/AN/A
SessionId<session><session>
ActionN/A<object>
Privilege-LevelN/AN/A
Authen-TypeN/AN/A
ServiceN/AN/A
UserN/A<account>
PortN/A<dport>
Remote-AddressN/A<dip>
Authen-MethodN/AN/A
Service-ArgumentN/AN/A
EnableSingleConnectN/AN/A
CiscoIOSN/AN/A
UseSingleConnectN/AN/A
AcsSessionIDN/AN/A
SelectedAccessServiceN/AN/A
SelectedCommandSetN/AN/A
Sequence-NumberN/AN/A
SelectedShellProfileN/AN/A
CPMSessionIDN/AN/A
ResponseN/A<result>
N/A<reason>
N/A<status>
Key1N/AN/A
Key2N/AN/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventClassification
1012194TACACS DiagnosticsBase RuleGeneral TACACS MessageInformation
Received TACACS+ Accounting RequestSub RuleTACACS+ Accounting With CommandInformation

LogRhythm Default v2.0

Regex IDRule NameRule TypeCommon EventClassification
1012658V 2.0 TACACS Diagnostics EventBase RuleGeneral TACACS MessageInformation
V 2.0 EVID 13000 Invalid TACACS+ Auth RequestSub RuleInvalid Authorization RequestWarning
V 2.0 EVID 13001 Invalid TACACS+ Accounting ReqSub RuleInvalid Accounting RequestError
V 2.0 EVID 13002 TACACS+ Listener StartSub RuleListener MessageInformation
V 2.0 EVID 13003 TACACS+ Listener StopSub RuleListener MessageInformation
V 2.0 EVID 13004 TACACS+ Listener FailSub RuleListener FailedError
V 2.0 EVID 13005 TACACS+ Auth Request ReceiveSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13006 TACACS+ Accounting Req ReceiveSub RuleAccounting Request ReceivedInformation
V 2.0 EVID 13007 TACACS+ Packet Header InvalidSub RuleInvalid Packet HeaderWarning
V 2.0 EVID 13008 TACACS+ Max Client Limit ReachSub RuleMaximum Clients ReachedWarning
V 2.0 EVID 13009 TACACS+ Client Connection FailSub RuleClient Connection FailedWarning
V 2.0 EVID 13010 TACACS+ Packet Invalid LengthSub RuleBad Packet LengthWarning
V 2.0 EVID 13011 Invalid TACACS+ Packet RequestSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13013 TACACS+ Authentication START ReqSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13014 TACACS+ Auth CONTINUE RequestSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13015 TACACS+ Auth Reply ReturnedSub RuleAuthentication Reply ReturnedInformation
V 2.0 EVID 13017 TACACS+ Packet Rcv Unknown DevSub RuleRequest Packet Received From Unknown HostNetwork Traffic
V 2.0 EVID 13019 TACACS+ Settings Obtain FailSub RuleFailed To Obtain SettingsError
V 2.0 EVID 13020 TACACS+ Default NW Dev SettingSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13021 System Overload TACACS+ Req DropSub RuleRequest Dropped - System OverloadedWarning
V 2.0 EVID 13023 Deny-Always Rule Command MatchSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13024 Permit Rule Command MatchSub RuleGeneral Information Log MessageInformation
V 2.0 EVID:13025 Permit Rule Command Fail To MatchSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13027 TACACS+ Auth Request MissingSub RuleGeneral Authorization WarningWarning
V 2.0 EVID 13029 Privilege Level Too HighSub RuleRequested Privilege Level Too HighError
V 2.0 EVID 13030 TACACS+ Auth Req Missing U/NSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13031 TACACS+ Auth Request MissingSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13032 TACACS+ Configuration Fatal ErrSub RuleConfiguration Access ErrorError
V 2.0 EVID 13034 TACACS+ Authorization ReplySub RuleAuthentication Reply ReturnedInformation
V 2.0 EVID 13035 TACACS+ Accounting ReplySub RuleAccounting ReplyInformation
V 2.0 EVID 13036 Shell Profile DenyAccessSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13037 Shell Profile Priv. Not Config.Sub RuleShell Profile Object Not ConfiguredInformation
V 2.0 EVID 13038 Request Fail - Crit Logging ErrSub RuleRequest Failed - Logging ErrorError
V 2.0 EVID 13039 Auth Req Not Contain New User PWSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13040 Empty String In The New PW FieldSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13041 Request Switches From LoginSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13042 Auth Req Confirm User New PWSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13043 Authentication Type Not SupportSub RuleAuthentication Method Not SupportedError
V 2.0 EVID 13044 TACACS Use Password PromptSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13045 Use PW Prompt From Global TACACSSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13046 ASCII Password Change RequestSub RulePassword Change RequestedInformation
V 2.0 EVID 13050 MSCHAP Invalid Flag ValueSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13051 TACACS Small Data Fieid SizeSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13052 TACACS Small Data Fieid SizeSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13060 Failed To Read TACACS Proxy ConSub RuleDropping Request - Failed To Read ConfigurationError
V 2.0 EVID 13061 Accounting Request ReceivedSub RuleAccounting Request ReceivedInformation
V 2.0 EVID 13062 TACACS Servers Failover PerformSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13063 Remote TACACS Server ForwardingSub RuleGeneral TACACS MessageInformation
V 2.0 EVID 13064 TACACS Proxy Rcv Incoming ReqSub RuleGeneral Proxy InformationInformation
V 2.0 EVID 13065 TACACS Proxy Rcv I/C Auth ReqSub RuleAuthentication Request ReceivedInformation
V 2.0 EVID 13066 TACACS Proxy Rcv I/C Auth ReqSub RuleAuthorization Request ReceivedOther Audit
V 2.0 EVID 13067 TACACS Proxy Rcv I/C Acc. ReqSub RuleAccounting Request ReceivedInformation
V 2.0 EVID 13068 TACACS Proxy Local Acc. PerformSub RuleProxy Performing Local AccountingInformation
V 2.0 EVID 13069 TACACS Proxy Remote Acc. PerformSub RuleProxy Performing Remote AccountingInformation
V 2.0 EVID 13070 TACACS Server Forward Req FailSub RuleRequest To Forward To Remote RADIUS Server FailedError
V 2.0 EVID 13071 Continue Flow (Seq_No>1)Sub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13072 TACACS Server Forward Req FailSub RuleRequest To Forward To Remote RADIUS Server FailedError
V 2.0 EVID 13073 TACACS+ Proxy Request FailedSub RuleGeneral Proxy FailureError
V 2.0 EVID 13074 TACACS Proxy Req Finish To ProcSub RuleGeneral Proxy SuccessInformation
V 2.0 EVID 13075 TACACS+ Proxy Req Won't ContinueSub RuleGeneral Proxy InformationInformation
V 2.0 EVID 13076 Rule Command Not SetSub RuleGeneral Information Log MessageInformation
V 2.0 EVID 13077 TACACS+ Acc. Invalid Packet ReqSub RuleInvalid Accounting RequestError
V 2.0 EVID 13078 TACACS+ Auth Invalid Packet ReqSub RuleInvalid Authorization RequestWarning
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.