Use this command to upload the SSH log file to the TFTP Server.
Ensure the following before using this command:
The TFTP Server IP address must be set using the command
set tftpserver ip <server_ip>Ensure the file with the corresponding file name exists on the TFTP Server with write permissions for all.
The file uploaded on the TFTP Server is the TAR file containing one or more zipped files. Perform the following steps to access the files:
Untar the file using the command
tar –xvf <filename>to get the individual zipped files.Each file must be unzipped using the command
gunzip <zipped_file>to view the file.
Syntax:
sshlogupload <filename>
A sample SSH log message is displayed below:
Sep 16 09:09:52 localhost kernel: SSHD_DROP:IN=eth0 OUT= MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 SRC=172.16.232.47 DST=172.16.199.89 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=4286 DF PROTO=TCP SPT=2821 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
Log Message Fields | Description |
|---|---|
SSHD_DROP | Denotes the number of minutes for activating the performance debugging on the Sensor |
IN=etho | Interface the packet was received from; empty value for locally generated packets |
OUT= | Interface the packet was sent to; empty value for locally received packets |
MAC=00:06:92:25:9d:80:00:0b:bf:a1:b7:fc:08:00 | The MAC field consisting of 14 entities, separated by colons, and this can read as the following: Dest MAC= 00:06:92:25:9d:80 — The destination MAC address Src MAC=00:0b:bf:a1:b7:fc — The source MAC address Type=08:00 — Ethernet frame carrying an IPv4 datagram |
SRC=172.16.232.47 | The source IP address |
DST=172.16.199.89 | The destination IP address |
LEN=48 | The total length of IP packet in bytes |
TOS=0x00 | The Type Of Service, “Type” field |
PREC=0x00 | The Type Of Service, “Precedence” field |
TTL=127 | The remaining Time To Live is 127 hops |
ID=4286 | The unique ID for this IP datagram shared by all fragments, if fragmented |
DF | Do not Fragment flag |
PROTO=TCP | The protocol name |
SPT=2821 | The source port |
DPT=22 | The destination port |
WINDOW=65535 | The number of bits specified on the “Window Scale” TCP option |
RES=0x00 | The reserved bits |
SYN | The synchronize flag and is only exchanged at TCP connection establishment |
URGP=0 | The urgent flag |
Applicable to:
NS-series Sensors