Parameter
firewall
accept
firewall action reject Firewall action executed (rejected package)
length
network interface
A.3
Syslog messages
This section describes selected Syslog messages. The selection is based on IEC 62443-3-3.
This means you can integrate these events into a central monitoring system (SIEM).
Identification and authentication of human users
Log Message
Standard
Description
Example
Severity
Facility
Log text
Standard
Description
Example
Severity
Facility
Log text
Standard
Description
Example
Severity
Facility
Log text
Standard
Description
Example
SCALANCE S615 Web Based Management
Configuration Manual, 11/2019, C79000-G8976-C388-08
Description
Firewall action executed (accepted package)
Length of the network packet (in bytes)
Format: %d
Symbolic name of a network interface
Format: %s
Console: User {user name} logged in.
IEC 62443-3-3 Reference: SR1.1
Valid login information that is specified during local login.
Console: User admin logged in.
Info
local0
Console: Default user {user name} logged in.
IEC 62443-3-3 Reference: n/a (NERC-CIP 007-R5)
User is logged in with default user name and password.
Console: Default user admin logged in.
Info
local0
{protocol}: User {user name} logged in from {ip address}.
IEC 62443-3-3 Reference: SR1.1
Valid login information that is specified during remote login.
WBM: User admin logged in from 192.168.0.1.
Info
local0
{protocol}: Default user {user name} logged in from {ip address}.
IEC 62443-3-3 Reference: n/a (NERC-CIP 007-R5)
User logged in with default user name and password.
SSH: Default user admin logged in from 192.168.0.1.
Appendix A
A.3 Syslog messages
Possible values or example
ACCEPT
REJECT DROP
52
vlan1
305