**Тип события** | **Пример записи Syslog**
|
**Вход в систему** | Apr 19 15:25:11 10.1.14.125 jumpserver: **login\_log** - {"backend": "Password", "backend\_display": "пароль", "city": "local", "datetime": "2023/04/19 15:18:36 +0800", "id": "cfc378e5-6337-4bf9-a8ac-15f33c2b0314", "ip": "10.1.10.35", "mfa": {"label": "отключено", "value": 0}, "reason": "", "reason\_display": "", "status": {"label": "успешно", "value": true}, "type": {"label": "Web", "value": "W"}, "user\_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, как Gecko) Chrome/112.0.0.0 Safari/537.36 Edg/112.0.1722.48", **"username": "admin"**}
|
**Ззагрузка файла** | Apr 19 15:27:26 10.1.14.125 jumpserver: **ftp\_log** - {"account": "root(root)", "asset": "10.1.12.182-root(10.1.12.182)", "date\_start": "2023/04/19 15:20:51 +0800", "filename": "**/tmp/vmware-root/файл.pdf**", "id": "6e7721c0-2091-49fb-8853-fc18e0a2e432", "is\_success": true, "operate": {"label": "uploading", **"value": "upload"**}, "org\_id": "00000000-0000-0000-0000-000000000002", "remote\_addr": "10.1.10.35", "user": "Administrator(admin)"}
|
**Скачивание файла** | Apr 19 15:28:08 10.1.14.125 jumpserver: **ftp\_log** - {"account": "root(root)", "asset": "10.1.12.182-root(10.1.12.182)", "date\_start": "2023/04/19 15:21:33 +0800", "filename": "**/tmp/vmware-root/файл.pdf**", "id": "113c0601-80c1-47d1-a053-5038fd89698c", "is\_success": true, "operate": {"label": "скачивание файла", **"value": "download"**}, "org\_id": "00000000-0000-0000-0000-000000000002", "remote\_addr": "10.1.10.35", "user": "Administrator(admin)"}
|
**Выполнение операции** | Apr 19 15:28:44 10.1.14.125 jumpserver: **operation\_log** - {"action": {"label": "update", "value": "update"}, "datetime": "2023/04/19 15:22:09 +0800", "id": "f844f014-2ac5-459d-abd0-ec8f853fa09c", "org\_id": "00000000-0000-0000-0000-000000000004", "org\_name": "SYSTEM", "remote\_addr": "10.1.10.35", "resource": "GLOBAL", "resource\_type": "System settings", "user": "Administrator(admin)"}
|
**Смена пароля** | Apr 19 15:29:58 10.1.14.125 jumpserver: **password\_change\_log** - {"change\_by": "Administrator(admin)", "datetime": "2023/04/19 15:23:23 +0800", "id": "0cd278ed-8335-49d5-a0c3-0211e9858441", "remote\_addr": "10.1.10.35", "user": "глобальный MFA(MFA)"}
|
**Запуск сессии доступа** | Apr 19 15:31:29 10.1.14.125 jumpserver: **host\_session\_log** - {"account": "root(root)", "account\_id": "49536b5e-bf06-4d16-bacd-7d628de3a3f2", "asset": "10.1.12.182-root(10.1.12.182)", "asset\_id": "dfba9962-7988-4d29-9b04-6f82dd8e02c3", "can\_join": true, "can\_replay": false, "can\_terminate": true, "comment": null, "date\_end": null, "date\_start": "2023/04/19 15:24:54 +0800", "has\_command": false, "has\_replay": false, "id": "4896b882-299a-4759-804e-32250f5b05b7", "is\_finished": false, "is\_success": true, "login\_from": {"label": "веб-терминал", "value": "WT"}, "org\_id": "00000000-0000-0000-0000-000000000002", "org\_name": "default", "protocol": "ssh", "**remote\_addr": "10.1.10.35"**, "terminal": {"id": "7076d4aa-4050-4a2f-855b-2af7a7bd6674", "name": "\[KoKo\]-jumpserver-v3-86c4b2fc7167"}, "type": {"label": "normal", "value": "normal"}, "user": "Administrator(admin)", "user\_id": "cdeb8352-9f45-46d9-8873-b3c7c53022fd"}
|
**Выполнение команды** | Apr 19 15:34:00 10.1.14.125 jumpserver: **session\_command\_log** - {"account": "root(root)", "asset": "10.1.12.182-root(10.1.12.182)", "id": "28400256-e9e2-4454-8127-4880fe5b9684", **"input": "free -h", "org\_id": "00000000-0000-0000-0000-000000000002", "output": "free -h\\r\\n total used free shared buff/cache available\\r\\nMem: 7.6G 4.3G 136M 28M 3.2G 3.0G"**, "remote\_addr": "10.1.10.35", "risk\_level": {"label": "обычный", "value": 0}, "session": "4896b882-299a-4759-804e-32250f5b05b7", "timestamp": 1681889159, "timestamp\_display": "2023/04/19 15:25:59 +0800", "user": "Administrator(admin)"}
|