Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation  Back up to About Overview 
[+] Expand All
[-] Collapse All

Using the Accounting Log File

RADIUS accounting events are recorded in the accounting log file. Accounting events include START messages, which indicate the beginning of a connection; STOP messages, which indicate the termination of a connection; and INTERIM messages, which indicate a connection is ongoing.

Accounting log files use comma-delimited, ASCII format, and are intended for import into a spreadsheet or database program. Accounting log files are located in the RADIUS database directory area by default, although you can specify an alternate destination directory in the [Configuration] section of the account.ini file. Accounting log files are named yyyymmdd.ACT, where yyyy is the four-digit year, mm is the month, and dd is the day on which the log file was created.

Accounting log files are kept for the number of days specified in the Settings page (described in Configuring the Log Retention Period), and are deleted after that to conserve disk space.

Note: An accounting log file is not created when there is no accounting request or activity from the client.

The current log file can be opened while SBR Carrier is running.

By default, SBR Carrier truncates a line in the accounting log when a non-printing character is encountered. You can set the ReplaceUnprintables parameter in the [Logging] section of radius.ini with a printable character which is used instead of non-printing characters when SBR Carrier writes messages to the accounting log file.

Note: Characters of ASCII decimal code 0 through 31 (ASCII hex code 0 through 1F) and 127 through 255 (ASCII hex code 7F through FF) are considered as non-printing characters. For more information about the ReplaceUnprintables parameter, see the SBR Carrier Reference Guide.

Accounting Log File Format

The first six fields in every accounting log entry are provided by SBR Carrier for your convenience in reading and sorting the file:

  • Date—The date when the event occurred
  • Time—The time when the event occurred
  • RAS-Client—The name or IP address of the RADIUS client sending the accounting record
  • Record-Type—START, STOP, INTERIM, ON, or OFF, the standard RADIUS accounting packet types
  • Full-Name—The fully distinguished name of the user, based on the authentication performed by the RADIUS server
  • Auth-Type—A number that indicates the class of authentication performed:
    0—Native13—Solaris User14—Solaris Group100—Tunnel User200—External Database(other)—Proxy

By default, the standard RADIUS attributes follow the Auth-Type identifier. See Standard RADIUS Accounting Attributes.

You can include vendor-specific attributes if the device sending the accounting packet supports them. For more information, see Vendor-Specific Attributes.

You can edit the account.ini initialization file to add, remove or reorder the standard RADIUS or vendor-specific attributes that are logged. For information about account.ini, refer to the SBR Carrier Reference Guide.

First Line Headings

The first line of the accounting log file is a file header that lists the attributes that have been enabled for logging in the order in which they are logged. The following example of a first line shows standard RADIUS headings in bold, and vendor-specific headings in regular text:

“Date”, ”Time”, “RAS Client”, “Record Type”, “Full Name”, “Auth Type”,“User Name”, “NAS Port”, “Acct Status Type”, “Acct Delay Time”, “Acct Input Octets”, “Acct Output Octets”, “Acct Session Id”, “Acct Authentic”, ”Acct Session Time”, “Acct Input Packets”, “Acct Output Packets”, “Acct Termination Cause”, “Acct Multi Session Id”, “Acct Link Count”, ”Acc Err Message”, “NauticaAcctSessionId”, ”NauticaAcctDirection”, “NauticaAcctCauseProtocol”, ”NauticaAcctCauseSource”, “TelebitAccountingInfo”, ”LastNumberDialedOut”, “LastNumberDialedInDNIS”, ”LastCallersNumberANI”, “Channel”, ”EventId”, ”EventDateTime”, “CallStartDateTime”, ”CallEndDateTime”, “DefaultDTEDataRate”, ”InitialRxLinkDataRate”, “FinalRxLinkDataRate”, ”InitialTxLinkDataRate”, “FinalTxLinkDataRate”, ”SyncAsyncMode”, “OriginateAnswerMode”, ”ModulationType”, “EqualizationType”, ”FallbackEnabled”, ”CharactersSent”, “CharactersReceived”, ”BlocksSent”, ”BlocksReceived”, “BlocksResent”, ”RetrainsRequested”, ”RetrainsGranted”, “LineReversals”, ”NumberOfCharactersLost”, “NumberofBlers”, ”NumberofLinkTimeouts”, “NumberofFallbacks”, ”NumberofUpshifts”, “NumberofLinkNAKs”, ”BackChannelDataRate”, “SimplifiedMNPLevels”, ”SimplifiedV42bisUsage”, “PW_VPN_ID”

Comma Placeholders

SBR Carrier writes accounting events to the accounting log file, If an event recorded in the accounting log file does not have data for every attribute, a comma placeholder marks the empty entry, so that all entries remain correctly aligned with their headings. For example, based on the first line of headings described above, the following is a valid accounting log entry, in which the value of the Acct-Status-Type attribute is 7:

“12/23/1997”, ”12:11:55”, ”RRAS”, ”AccountingOn”,,,,,7,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

Standard RADIUS Accounting Attributes

Table 122 lists the standard RADIUS accounting attributes defined in RFC 2866, RADIUS Accounting.

Table 122: Standard RADIUS Accounting Attributes




The name of the user as received by the client.


The port number on the client device.


A number that indicates the beginning or ending of the user service:







Indicates how many seconds the client has been trying to send this record, which can be subtracted from the time of arrival on the server to find the approximate time of the event generating this request.


Number of octets (bytes) received by the port over the connection; present only in STOP records.


Number of octets (bytes) sent by the port over the connection; present only in STOP records.


Identifier used to match START and STOP records in a log file.


Indicates how the user was authenticated by RADIUS, the network access device (local), or another remote authentication protocol:





Elapsed time of connection in seconds; present only in STOP records.


Number of packets received by the port over the connection; present only in STOP records.


Number of packets sent by the port over the connection; present only in STOP records.


Number that indicates how the session was terminated; present only in STOP records:

1—User Request

2—Lost Carrier

3—Lost Service

4—Idle Timeout

5—Session Timeout

6—Admin Reset

7—Admin Reboot

8—Port Error

9—NAD Error

10—NAD Request

11—NAD Reboot

12—Port Unneeded

13—Port Preempted

14—Port Suspended

15—Service Unavailable


17—User Error

18—Host Request


Unique accounting identifier to make it easy to link together multiple related sessions in a log file.


The count of links that are known to have been in a given multi-link session at the time the accounting record is generated.


Modified: 2017-03-07