*Sep 12 06:27:31.044: %KAZULOG-6-STEPMARK: Message from tty434(user id: cisco): STEP1-BEGIN-20260912-152710 *Sep 12 06:27:31.069: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.100.3.1 (tty = 0) for user 'cisco' using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' closed *Sep 12 06:27:57.044: %SYS-4-INSECURE_CONFIG: Module: SSH - Command: crypto key generate rsa ... - Reason: SSH host key uses insufficient key length - Remediation: Use SSH RSA host key with a minimum length of 3072 bits for enhanced security *Sep 12 06:28:01.421: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.100.3.1 (tty = 0) using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded *Sep 12 06:28:01.754: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: cisco] [Source: 10.100.3.1] [localport: 22] at 06:28:01 UTC Sat Sep 12 2026 *Sep 12 06:28:01.755: %SSH-5-SSH2_USERAUTH: User 'cisco' authentication for SSH2 Session from 10.100.3.1 (tty = 0) using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded *Sep 12 06:28:02.267: %SYS-5-CONFIG_I: Configured from console by cisco on vty0 (10.100.3.1) *Sep 12 06:28:02.529: %SYS-6-LOGOUT: User cisco has exited tty session 434(10.100.3.1) *Sep 12 06:28:02.529: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.100.3.1 (tty = 0) for user 'cisco' using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' closed *Sep 12 06:28:04.079: %LINK-5-CHANGED: Interface GigabitEthernet1, changed state to administratively down *Sep 12 06:28:05.080: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1, changed state to down *Sep 12 06:28:14.865: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.100.3.1 (tty = 0) using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded *Sep 12 06:28:15.130: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: cisco] [Source: 10.100.3.1] [localport: 22] at 06:28:15 UTC Sat Sep 12 2026 *Sep 12 06:28:15.130: %SSH-5-SSH2_USERAUTH: User 'cisco' authentication for SSH2 Session from 10.100.3.1 (tty = 0) using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded *Sep 12 06:28:15.718: %SYS-6-LOGOUT: User cisco has exited tty session 434(10.100.3.1) *Sep 12 06:28:15.720: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.100.3.1 (tty = 0) for user 'cisco' using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' closed *Sep 12 06:28:16.081: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.100.3.1 (tty = 0) using crypto cipher 'aes128-gcm@openssh.com', hmac 'hmac-sha2-256-etm@openssh.com' Succeeded *Sep 12 06:28:16.183: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: cisco] [Source: 10.100.3.1] [localport: 22] at 06:28:16 UTC Sat Sep 12 2026