The audit messages in this section are from the Cryptographic Security Platform Vault for KMIP.

In the table below, we list many of the audit messages and show:

  • Whether an Alert is also generated.
  • The severity (L=Low, M=Medium, H=High).
  • What the resolution is if any action should be taken.
  • In the Message column, a %s represents a string value. For example, in the following message:

    Added user %s to group %s

    The actual message will be displayed with the name of the user and group, for example:

    Added user fred to group IT

Msg ID

Message

Severity

Alert?

Category

300

{user_name} created the policy '{policy_name}

M

false

KMIP

301

{user_name} updated the policy '{policy_name}'. New policy version is {policy_version}.

M

false

KMIP

302

{user_name} deleted the policy '{policy_name}'

M

false

KMIP

303

{user_name} changed the current version of the policy '{policy_name}'. Current policy version is {policy_version}.

M

false

KMIP

400

KMIP Client Certificate '{name}' created

H

false

KMIP

401

KMIP Client Certificate '{name}' created using Certificate Signing Request

H

false

KMIP

402

KMIP Client Certificate '{name}' deleted

H

false

KMIP

403

KMIP Client Certificate '{name}' created using uploaded Certificate

H

false

KMIP

500

User '{user_name}' logged in successfully.

H

false

KMIP

501

Active Directory login for {username} succeeded but Kmip portal failed to get information about user. The user might not belong to the Active Directory Domain {domain_name} or user/group base dn in Active Directory configuration might be wrong. Please contact Kmip Administrator to validate the Active Directory setup.

H

false

KMIP

502

Login failure for Active Directory user {username}

H

false

KMIP

503

User '{user_name}' logged in successfully using Personal Access Token {token_name}.

H

false

KMIP

504

{user_name} enabled authentication inheritance

M

false

KMIP

505

Authentication settings for inheriting vault {vault_name} {action} by System Admin

M

false

KMIP

600

{user_name} updated AD Setting '{ad_setting_name}'

M

false

KMIP

601

{user_name} changed AD Domain from '{old_ad_setting_name}' to '{ad_setting_name}'

M

false

KMIP

602

{user_name} added AD Setting '{ad_setting_name}'

M

false

KMIP

700

KMIP Request - Operation: {op}, Object: {obj}, UUID: {uuid} from KMIP Client - {user} (IP: {client_ip})

H

false

KMIP

701

KMIP Response - Operation: {op}, Object: {obj}, UUID: {uuid}, Result: {result}, from KMIP Client - {user} (IP: {client_ip})

H

false

KMIP

702

KMIP Action Request from WebGUI. Action: Revoke, UUID: {uuid}. Revocation Code: {revcode}, Revocation message: {revmsg}, Result: {result} (IP: {client_ip})

H

false

KMIP

703

KMIP Action Response from WebGUI. Action: {op}, UUID: {uuid}, Result: {result} (IP: {client_ip})

H

false

KMIP

800

{user_name} updated kmip '{kmip_name}' settings. 'degraded mode availability' {degraded_mode}. 'OIDC authentication' {oidc}.

M

false

KMIP

801

{user_name} updated kmip '{kmip_name}' settings of authentication method to AD based authentication with Active Directory domain '{ad_domain}'

M

false

KMIP

802

{user_name} updated kmip '{kmip_name}' settings about KCM information with 'kcm ip: ' {kcm_ip}.

M

false

KMIP

803

{user_name} updated kmip '{kmip_name}' settings of authentication method to OIDC based authentication

M

false

KMIP

900

{username} updated KEK Setting

M

false

KMIP

901

{username} enabled KMIP KEK wrapping

M

false

KMIP

902

{username} disabled KMIP KEK wrapping

M

false

KMIP

1000

Successfully completed rekey of KMIP objects

L

false

KMIP

1001

Successfully completed decryption of KMIP objects

L

false

KMIP

1002

Successfully started rekey of KMIP objects

L

false

KMIP

1100

Successfully reset KMIP vault {tenant}

L

false

KMIP

1200

{user_name} created the user '{name}'

M

false

KMIP

1201

{user_name} deleted the user '{name}'

M

false

KMIP

1202

{user_name} updated the user '{name}'

M

false

KMIP

1203

Account {user_name} locked for 5 minutes due to repeated login failures

H

false

KMIP

1204

Account {user_name} disabled due to repeated login failures

H

false

KMIP

1205

Login failure for Local user {username} from {client_ip}. Reason: {reason}

H

false

KMIP

1206

Successfully updated password for user: {username}

H

false

KMIP

1207

Account {user_name} enabled Two-factor authentication

L

false

KMIP

1208

Account {user_name} disabled Two-factor authentication

L

false

KMIP

1209

{user_name} updated the local user password policy

M

false

KMIP

1210

{user_name} enforced Two-factor authentication

M

false

KMIP

1211

{user_name} removed enforcement of Two-factor authentication

M

false

KMIP

1300

{user_name} created Personal Access Token {token_name}

M

false

KMIP

1301

{user_name} {update_info} Personal Access Token {token_name}

M

false

KMIP

1302

{user_name} deleted Personal Access Token {token_name}

M

false

KMIP

1400

{user_name} created OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1401

{user_name} failed to create OIDC user {oidc_user_email}

M

false

KMIP

1402

{user_name} updated OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1403

{user_name} failed to update OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1404

{user_name} deleted OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1405

{user_name} failed to delete OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1406

{user_name} created registration link for OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1407

{user_name} failed to create registration link for OIDC user {oidc_user_email}: {oidc_user_guid}

M

false

KMIP

1408

Login failure for OIDC user {username} from {client_ip}. Reason: {reason}

M

false

KMIP