Syntax
./nnl-mgmt.sh audit_log verify (-file <path-to-file> | -dir <dir-path>) [-checksum <startingChecksum> ]Parameter | Description |
|---|---|
file | Either file or dir must be provided. The full path name of the file you want to verify. |
dir | The directory containing the log files you want verified. |
checksum | Log file line’s checksum value, to start verification from that line. |
Description
Performs a checksum verification of each line in an audit log to verify that no one has tampered with the log files. The verifier can check a .log file, a .gz file (compressed log file), or it can verify all the log files in a directory. By default, the log file is named nnl-audit-<tenantID>-<hostname>.log, an example is nnl-audit-default-uaf-latest-build.log. Note that the nnl-mgmt.sh audit_log verify command does not work on the Runtime Audit Log in CSV.
Every line in a log file has a checksum. Use this value if you want the verification operation to start from a specific line in the log file.
Example
./nnl-mgmt.sh audit_log verify -file /opt/tomcat-9.0.16/logs/auditlogs/default/nnl-audit-default-myhostname.log -checksum DjViSKtRpy0AuWeA0tp2-fkfNgC1SC4zXjIujcTa_ks
Date/Time ==> Thu Sep 24 01:23:05 UTC 2020
Processing file ==> /opt/tomcat-9.0.16/logs/auditlogs/default/nnl-audit-default-myhostname.log
For tenant ==> default
Checksum Verification succeeded for file : /opt/tomcat-9.0.16/logs/auditlogs/default/nnl-audit-default-myhostname.log
1 : Checksum Verification succeeded for file : /opt/tomcat-9.0.16/logs/auditlogs/default/nnl-audit-default-myhostname.log