Configure Audit Log Options in FIPS Mode

Learn to configure audit log options in FIPS mode.

Configure Audit Log Options on Your Device in FIPS Mode

Only authenticated administrators are authorized to delete locally stored audit data.

To configure audit log options:

  1. Specify the number of files to be archived in the system logging facility.
  2. Specify the file in which to log data.
  3. Specify the size of files to be archived.
  4. Specify the priority and facility in messages for the system logging facility.
  5. Log system messages in a structured format.
  6. Commit the changes:

Junos OS Log File Management and Storage Behavior

The Junos OS maintains logs through active log file and a set of archived log files (10 files by default, but configurable 1 through 1000 files). When the active file log reaches its maximum file size (1 GB by default, but configurable 65536 to 1073741824 bytes, that is 64 KB to 1 GB), the login utility performs the following steps:

  1. Archiving the Active File:

    • When the active log file reaches its maximum size the logging utility:

      • Closes and compresses the log file

      • Saves the file as logfile.0.gz.

      • Creates an active log file for ongoing logging.

  2. Managing Older Archives:

    • When the new active file log reaches the maximum size, the existing logfile.0.gz is renamed to logfile.1.gz.

    • The current active log file is then closed, compressed, and renamed to logfile.0.gz.

  3. Managing Archive Limits:

    • When the maximum number of archived files is reached and the active log file reaches its size limit, the oldest archived file is deleted.

    • This ensures space for the newest archive file while maintaining the configured number of backups.

Storage Management for Syslog Files

A 1 GB syslog file takes approximately 0.25 GB of storage when archived. Syslog files can consume all allocated storage in to /var file, which is platform specific.

When the filesystem reaches 92% storage capacity an event is raised to the administrator. However, the event process continues using the reserved storage blocks to ensure uninterrupted logging till the administrator frees the storage.

Storage Exhaustion Management

When the /var file storage exhausted, the system logs a final entry reporting No space left on device and terminates the logging. The appliance continues to operate in the event of exhaustion of audit log storage space.

Sample Code Audits of Configuration Changes

This sample code audits all changes to the configuration secret data and sends the logs to a file named Audit-File:

This sample code expands the scope of the minimum audit to audit all changes to the configuration, not just secret data, and sends the logs to a file named Audit-File:

Example: The System Logging of Configuration Changes

This example shows a sample configuration and makes changes to users and secret data. It then shows the information sent to the audit server when the secret data is added to the original configuration and committed with the load command.

The new configuration changes the secret data configuration statements and adds a new user.