Include Logout in Session Records

Information

The session record flags are specified as a comma-separated value list of one or more of the following flags: login, logout, and refresh. This option specifies whether logout entries should be included in the Session records. The default is enabled.

Solution

Log into the Cisco APIC SSH Console:

Enter 'configure' mode

Ensure session-record-flags includes a value of logout

Item Details

Audit Name: Tenable Cisco ACI

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Cisco_ACI

Control ID: d20197e41d852cf17c9fd7d458731b1c6af7e903764363008abec75f26e87a93