You can use 3CDaemon or Kiwi Syslog Daemon if you do not have a syslog server.
After you have configured a syslog server, run the following commands on the PacketShaper to enable audit log being pushed to the syslog server.
#
setup syslog add host:<syslog server IP address> output:13,7
setup syslog state on
#
Examples with syslog server IP address 10.10.10.10:
setup syslog add host:10.10.10.10 output:13,7
setup syslog state on
Examples of syslog output:
May 23 08:48:32 10.10.10.111 AUDT-6-Audit: Unit Edited: 175-10014148, logged in via "CLI (touch)"
May 23 08:49:12 10.10.10.111 AUDT-6-Audit: Unit Edited: 175-10014148, Set inbound link to 10000000.
May 23 09:29:39 10.10.10.111 AUDT-6-Audit: Unit Edited: 175-10014148, Reset the class tree and reverted to default tree.
May 23 09:29:45 10.10.10.111 AUDT-6-Audit: Unit Edited: 175-10014148, Cannot load the current configuration configuration from file testing.ldi.