Review audit events
Review these examples of audit events and records that appear in Common Criteria evaluated configuration.
The record contents are shown in McAfee ESM format. To set the format to use, see the Add rules for forwarding audit data from Management Servers topic in the Reconfiguring the SMC and Security Engines chapter in the Forcepoint Network Security Platform Product Guide. Some of the more common McAfee ESM fields are described in the following table.
| Field | Description |
|---|---|
| Timestamp | Log entry creation time. |
| NodeId | IP address of the engine or server that sent the log entry. |
| Facility | The engine subsystem that created the log entry. |
| CompId | The identifier of the creator of the log entry. |
| InfoMsg | A description of the log event that further explains the entry. |
| SenderType | The type of engine or server that sent the log entry. |
| EventId | Event identifier, unique within one sender. |
| UserOriginator | Administrator who triggered the audit event. |
| ClientIpAddress | Address of the client that triggered the audit event. |
| Type | Log entry severity type. |
| TypeDescription | Type of action that triggered the audit entry. |
| Result | Result state after the audited event. |
| ObjectName | Elements being manipulated in the audit event. |
| SituationId | The identifier of the situation that triggered the log event. |
| Situation | Situation name. |
| FAU_GEN.1.1 a) | |
|---|---|
| Auditable event | Start up and shutdown of the audit functions. |
| Startup of SMC Appliance |
|
| Shutdown of SMC Appliance |
|
| Startup of Security Engine |
|
| Shutdown of Security Engine |
|
| FAU_GEN.1.1 c) | |
|---|---|
| Auditable event | Administrative login and logout |
| Administrative login |
|
| Administrative logout |
|
| FMT_SMF.1, FAU_GEN.1.1 c) | |
|---|---|
| Auditable event | Security related configuration changes |
| Audit server configuration changes |
|
| Configuring reference identifier for the peer |
|
| Modification of administrator accounts |
|
| Modification of administrator accounts (Continued) |
|
| Logon banner change |
|
| Minimum password length |
|
| Remote session timeout change |
|
| Configure authentication failure parameters for FIA_AFL.1 |
|
| Configure authentication failure parameters for FIA_AFL.1 (Continued) |
|
| Auditable event | Configuration of time |
| Configuration of a new time server |
|
| Auditable event | Configuration of the cryptographic functionality |
| Configure the cryptographic functionality for TLS |
|
| Configure the cryptographic functionality for TLS (continued) |
|
| Configure the cryptographic functionality for NTP |
|
| Auditable event | Generating / import of, changing, or deleting of cryptographic keys |
| Creation of a TLS private key () |
|
| Certificate signing request |
|
| Import signed certificate |
|
| Deletion (from Trash) |
|
| Import of a trusted certificate authority (CA) |
|
| Import of a private key and a certificate |
|
| Removal (Deletion) of a Trusted Certificate Authority |
|
| Auditable event | Resetting passwords |
| Password reset |
|
| FCS_NTP_EXT.1, FAU_GEN.1.1 c) | |
|---|---|
| Configuration of a new time server |
|
| Removal of configured time server |
|
| Manual time change |
|
| FMT SMF.1/FFW FAU_GEN.1.1 c) | |
|---|---|
| Engine filtering rule change |
|
| Engine security policy change |
|
| Engine security policy change (add rule) |
|
| Engine security policy change (delete rule) |
|
| Engine security policy change (create policy) |
|
| Engine security policy change (upload policy) |
|
| Firewall security policy change (delete policy) |
|
| FMT_SMF.1/VPN, FAU_GEN.1.1 c) VPN security policy change | |
|---|---|
| VPN security policy change (adding rule) |
|
| VPN security policy change (modify rule) |
|
| VPN security policy change (delete rule) |
|
| FPT_STM_EXT.1 | |
|---|---|
| NTP time change |
|
| NTP time change (Continued) |
|
| FCS_TLSC_EXT.1 | |
|---|---|
| Auditable event | TLS client sessions |
| Failure to establish a TLS client session |
|
| FCS_TLSS_EXT.1,FCS_HTTPS_EXT.1,FTP_TRP.1/Admin | |
|---|---|
| Auditable event | HTTPS and TLS sessions, and trusted path |
| Initiation of an HTTPS or TLS session, or trusted path |
|
| Termination of an HTTPS or TLS session, or trusted path |
|
| Failure to establish an HTTPS or TLS session, or trusted path |
|
| FCS_TLSS_EXT.2 | |
|---|---|
| Auditable event | TLS sessions |
| Failure to authenticate the client (SMC as a server) |
|
| Failure to authenticate the client (Security Engine as a server) |
|
| FFW_RUL_EXT.1 | |
|---|---|
|
Half-open connection limit |
|
| Auditable event | Application of rules configured with the 'log' operation |
| Connection allowed |
|
| Connection discarded |
|
| FFW_RUL_EXT.2 | |
|---|---|
| Auditable event | Dynamical definition of rule and establishment of a session |
| Dynamical definition of rule and establishment of a session |
|
| FIA_AFL.1 | |
|---|---|
| Auditable event | Unsuccessful login attempt limit is met or exceeded |
| Prevent the offending remote Administrator from successfully authenticating until an Administrator defined time period has elapsed |
|
| FIA_UAU_EXT.2, FIA_UIA_EXT.1 | |
|---|---|
| Auditable event | All use of identification and authentication mechanism |
| Local session identification and authentication failures |
|
| Local session identification and authentication failures (continue) |
|
| Local session identification and authentication failures (Continued) |
|
| Local session successful identification and authentication |
|
| Remote session identification and authentication failures |
|
| Remote session identification and authentication succeeds |
|
| FIA_X509_EXT.1 | |
|---|---|
| Auditable event | Unsuccessful attempt to validate a certificate |
| Unsuccessful attempt to validate a certificate |
|
| FIA_X509_EXT.1/ITT | |
|---|---|
| Auditable event | Unsuccessful attempt to validate a certificate |
| Unsuccessful attempt to validate a certificate (Security Engine) |
|
| Unsuccessful attempt to validate a certificate (Security Engine (continued) ) |
|
| Unsuccessful attempt to validate a certificate (SMC) |
|
| FMT_MOF.1/ManualUpdate | |
|---|---|
| Auditable event | Any attempt to initiate a manual update |
| Any attempt to initiate a manual update |
|
| FMT_MOF.1/Functions | |
|---|---|
| Auditable event | Modification of the behavior of the audit functionality when Local Audit Storage Space is full |
| Modification of the behavior of the audit functionality when Local Audit Storage Space is full |
|
| Modification of the behavior of the transmission of audit data to an external IT entity |
|
| Modification of the behavior of the handling of audit data |
|
| FPT_ITT.1 | |
|---|---|
| Auditable event | TLS communication between the distributed TOE components |
| Initiation of the trusted channel (Security Engine) |
|
| Termination of the trusted channel (Security Engine) |
|
| Failure of the trusted channel functions (Security Engine) |
|
| Initiation of the trusted channel (SMC) |
|
| Termination of the trusted channel (SMC) |
|
| Failure of the trusted channel functions (SMC) |
|
| FPT_TUD_EXT.1 | |
|---|---|
| Auditable event | Initiation of update |
| Verification of image (SMC) |
|
| SMC Appliance update |
|
| Successful SMC update |
|
| Failed SMC Appliance update |
|
| Verification of image (Security Engine) |
|
| Initiation of Security Engine Engine update |
|
| Result of the Security Engine Engine update attempt |
|
| Failed Security Engine Engine update |
|
| FTA_SSL.3 | |
|---|---|
| Auditable event | The termination of a remote session by session locking mechanism |
| Termination of a remote session by session locking mechanism |
|
| FTA_SSL.4 | |
|---|---|
| Auditable event | The termination of an interactive session |
| Termination of local administrative session |
|
| Termination of remote administrative session |
|
| FTA_SSL_EXT.1 | |
|---|---|
| Auditable event | Local session termination |
| Local session termination |
|
| Local session termination (continued) |
|
| FTP_ITC.1 | |
|---|---|
| Auditable event | Trusted channel functions |
| Initiation of the trusted channel |
|
| Termination of the trusted channel |
|
| Auditable event | Failure of the trusted channel functions |
| TLS failure |
|
| Connection failure |
|
| FTP_TRP.1/Admin | |
|---|---|
| Auditable event | Trusted path functions |
| Initiation of the trusted path |
|
| Termination of the trusted path |
|
| Failure of the trusted path functions |
|
| FTP_TRP.1/Join | |
|---|---|
| Auditable event | Trusted path functions |
| SMC registration (Initiation) |
|
| SMC registration (Termination) |
|
| SMC registration (Failure) |
|
| Security Engine registration (Initiation) |
|
| Security Engine registration (Termination) |
|
| Security Engine registration (Failure) |
|
| FCO_CPC_EXT.1 | |
|---|---|
| Auditable event | Enabling and disabling communication between the Security Engine and SMC. |
| Enabling from the Security Engine |
|
| Disabling from the Security Engine Engine |
|
| Enabling from the SMC |
|
| Disabling from the SMC |
|
| FCS_IPSEC_EXT.1 IPsec Protocol | |
|---|---|
| Auditable event | |
| Decisions to DISCARD network packets processed by the TOE |
DISCARD
|
| Decisions to BYPASS network packets processed by the TOE |
BYPASS
|
| Decisions to PROTECT network packets processed by the TOE |
PROTECT
|
| IPsec SAs |
Failure to establish an IPsec SA
|
|
IPsec SA establishment
|
|
|
IPsec SA termination
|
|
| FIA_X509_EXT.1/Rev X.509 Certificate Validation (VPN) | |
|---|---|
| Auditable event | Unsuccessful attempt to validate a certificate |
| Unsuccessful attempt to validate a peer certificate |
Unsuccessful attempt to validate a peer certificate: No CRL service
|
|
Unsuccessful attempt to validate a peer certificate: Untrusted root
CA
|
|
|
Unsuccessful attempt to validate a peer certificate: Certificate revoked by
OCSP
|
|
|
Unsuccessful attempt to validate a peer certificate: Certificate revoked by
CRL
|
|
|
Unsuccessful attempt to validate a peer certificate: Invalid OCSP
signer
|
|
| Any addition, replacement or removal of trust anchors in the TOE's trust store |
Import of a trusted certificate authority
|
|
Configuration of trusted certificate authorities
|
|
|
Removal (deletion) of a trusted certificate authority
|
|
| FMT SMF.1/VPN FAU_GEN.1.1 c) All administrative actions (VPN) | |
|---|---|
| Auditable event | Generating / import of, changing, or deleting of cryptographic keys |
| Generating / import of, changing, or deleting of cryptographic keys |
Creation of a VPN private key
|
|
Certificate signing request
|
|
|
Import of a signed certificate
|
|
| Configuration of remote VPN client session timeout |
|
| Configuration of the cryptographic functionality |
Configuration of IPSec functionality
|
| Configuration of the lifetime for IKEv2 SAs |
Configuration of IKEv2 SA lifetimes
|
|
Configuring IKEv2 Child SA lifetimes
|
|
| FPF_RUL_EXT.1 Packet Filtering Rules | |
|---|---|
| Auditable event | Application of rules configured with the log operation |
| Application of rules configured with the 'log' operation (VPN) | Drop traffic
|
Permit traffic (BYPASS)
|
|
Permit traffic (PROTECT)
|
|
| FTP_ITC.1/VPN Inter-TSF Trusted Channel (VPN Communications) | |
|---|---|
| Auditable event | Trusted channel functions |
| Initiation of the trusted channel |
|
| Termination of the trusted channel |
|
| Failure of the trusted channel functions |
|
| FTA_TSE.1.1 TOE Session Establishment | |
|---|---|
| Auditable event | |
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) |
Configuration of attributes used to deny establishment of remote VPN client session (time, day)
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued) |
|
| FAU_GEN.1/VPN Audit Data Generation (VPN Gateway) | |
|---|---|
| Auditable event | |
| Indication that TSF self-test was completed (NGFW) |
|
| Indication that TSF self-test was completed (SMC) |
|
| Failure of self-test (NGFW) |
|
| Failure of self-test (SMC) |
|