Logs from the CLI

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Logs from the CLI

L3 Networker

We've had suspicions that there have been logins from an unknown source via the console.

 

"User admin logged in via CLI from Console"

 

None of the team have stated they logged in around 1am to the box, and the room is locked with a pin.

 

Is there anyway, apart from comparing configurations, and seeing what admins have logged on (I only have one admin user account), that I could potentially see what the activity was of the user that logged in? I.e what commands they ran in the CLI?

 

I don't believe there is a way, but would like to know people's thoughts.


Cheers

Jack

4 REPLIES 4

L3 Networker

1.png2.pngThe first picture shows the time of the login, and the second picture shows access requests into where the Palo is installed.

 

 

config changes will be stored in the config log, furthermore you could review executed 'runtime' commands by logging into the cli and using the 'up' arrow to review all issued commands (up to about 40 previously executed commands are stored in history) in case only some debug commands were executed.

 

I'd recommend setting up several different (personalized if possible) administrator accounts which you can grant more/less access than that person or group requires, you can even disable CLI access for accounts

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L3 Networker

Could this be your issue?

https://m.reddit.com/r/networking/comments/4oi72x/palo_alto_owners_get_any_unexpected_logins_from/

 

Quote from the topic:

Thank you for contacting Palo Alto Networks tech support. We have confirmed this affects only 3K platforms. Engineering is working on BUG-98344 to fix this cosmetic issue and it will not occur with installing further dynamic updates.

Reaper, thanks for the reply, that is what will need carrying out in future for sure.

 

Vieplis, ah, thank you! This seems very relevant. I will have to keep an eye on this.

 

Thanks

Jack

  • 2667 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!