
Logs
X Family LSM User’s Guide V 2.5.1 99
Log Maintenance
The X family device maintains two files for each log: a historical log file and a current log file. When the
current log file reaches the default size (4MB), the log is de-activated and saved as the historical file. A
new log file is started as the current log. If a historical file already exists, that file is deleted. When the
log is rolled over, the device generates a message in the Audit log. To save log all data and create a
backup, configure the device to offload log messages to a remote system log.
You can reset a log from its menu page, or use the Reset function available on the System Summary
page.
For details, refer to the following sections:
• “Alert Log” on page 99
• “Audit Log” on page 100
• “IPS Block Log” on page 101
• “Firewall Block Log” on page 102
• “Firewall Session Log” on page 103
• “VPN Log” on page 104
• “System Log” on page 105
• “Managing Logs” on page 106
• “Configuring Remote System Logs” on page 105
Alert Log
The Alert log contains information about network traffic that triggers IPS filters configured with a
Permit + Notify or Permit+Notify+Trace action set. Any user can view the log, but only administrator
and super-user level users can print the log.
To maintain a complete history of entries and provide a backup, you can configure the X family device
to send Alert Log entries to a remote syslog server from the Notification Contacts page. For details, see
“
Notification Contacts” on page 52.
An Alert log entry contains the following fields:
Table 5–1: Alert Log Field Descriptions
Column Description
Log ID A system-assigned Log ID number
Date/Time A date and time stamp in the format year-month-date hour:minute:second
Severity Indicates the severity of the triggered filter. Possible values include: Critical,
Major, Minor, and Low
Filter Name The name of the IPS filter that was triggered
Protocol The name of the protocol that the action affects
Security Zone
(pair)
The Security Zone pair where the alert occurred (LAN -WAN, for example)
Comentarios a estos manuales