As the title says, the default audit log entry in CAS 6.2.X for submission of a one-time token by a user incorrectly logs the one-time token value under the "WHO :" field when the one-time token provided by the user is incorrect.
Example log entry :
Audit trail record BEGIN
=============================================================
WHO: 039328
WHAT: Supplied credentials: [OneTimeTokenCredential(token=039328)]
ACTION: AUTHENTICATION_FAILED
APPLICATION: CAS
WHEN: Fri Dec 18 10:10:48 EET 2020
CLIENT IP ADDRESS: [redacted]
SERVER IP ADDRESS: [redacted]
=============================================================