< Home

audit session aging-time

Function

The audit session aging-time command sets session aging time for an audit policy.

The undo audit session aging-time command restores the default setting.

Format

audit session aging-time interval

undo audit session aging-time

Parameters

Parameter Description Value
interval Specifies the session aging time. The value is an integer ranging from 1 to 600, in seconds.

Views

System view

Default Level

3: Management level

Usage Guidelines

When flows match an audit policy, session entries are created for them. Session entries are similar to forwarding entries, except that the session entries record the audit status, but not forwarding status. For the same flow:

  • If the aging time of the session entry is too short, the audit process will end prematurely after the entry expires. As a result, the record information may be incomplete.
  • If the aging time of the session entry is too long and the traffic volume is large, no new session can be established until the old one is deleted. As a result, some audit information is lost.

By default, the session aging time is 15s.

Example

# Set the session aging time to 100s for an audit policy.

<sysname> system-view
[sysname] audit session aging-time 100
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >