我有一个 Cisco VPN(不确定具体是哪个硬件),它的日志被转发到我们的 Splunk 服务器。看来用户名已被编辑。我看到的都是星号。这是可以在 VPN 上更改的内容吗?如何更改?希望可以回答问题的设备之间有足够的一致性。谢谢!
截图如下:
IP xx.xx.xx.xx
_raw Jun 26 10:23:31 xx.xx.xx.xx %ASA-6-113005: AAA user authentication Rejected : reason = Invalid password : server = xx.xx.xx.xx : user = ***** : user IP = xx.xx.xx.xx
_time 2014-06-26T10:23:31.000-0400
app
date_hour 10
date_mday 26
date_minute 23
date_month june
date_second 31
date_wday thursday
date_year 2014
date_zone local
eventtype
host xx.xx.xx.xx
ids_type
index main
linecount 1
pid
process %ASA-6-113005
product
punct __::_..._%--:_____:__=___:__=_..._:__=_*****_:___=
reason Invalid
server xx.xx.xx.xx
source syslog
sourcetype syslog
splunk_server xx.xx.xx
tag::eventtype
timeendpos 15
timestartpos 0
user *****
vendor