HP X Unified Security Platform Series Manual de usuario Pagina 115

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 333
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 114
Logs
X Family LSM User’s Guide V 2.5.1 99
Log Maintenance
The X family device maintains two files for each log: a historical log file and a current log file. When the
current log file reaches the default size (4MB), the log is de-activated and saved as the historical file. A
new log file is started as the current log. If a historical file already exists, that file is deleted. When the
log is rolled over, the device generates a message in the Audit log. To save log all data and create a
backup, configure the device to offload log messages to a remote system log.
You can reset a log from its menu page, or use the Reset function available on the System Summary
page.
For details, refer to the following sections:
Alert Log” on page 99
Audit Log” on page 100
IPS Block Log” on page 101
Firewall Block Log” on page 102
Firewall Session Log” on page 103
VPN Log” on page 104
System Log on page 105
Managing Logs on page 106
Configuring Remote System Logs” on page 105
Alert Log
The Alert log contains information about network traffic that triggers IPS filters configured with a
Permit + Notify or Permit+Notify+Trace action set. Any user can view the log, but only administrator
and super-user level users can print the log.
To maintain a complete history of entries and provide a backup, you can configure the X family device
to send Alert Log entries to a remote syslog server from the Notification Contacts page. For details, see
Notification Contacts” on page 52.
An Alert log entry contains the following fields:
Table 5–1: Alert Log Field Descriptions
Column Description
Log ID A system-assigned Log ID number
Date/Time A date and time stamp in the format year-month-date hour:minute:second
Severity Indicates the severity of the triggered filter. Possible values include: Critical,
Major, Minor, and Low
Filter Name The name of the IPS filter that was triggered
Protocol The name of the protocol that the action affects
Security Zone
(pair)
The Security Zone pair where the alert occurred (LAN -WAN, for example)
Vista de pagina 114
1 2 ... 110 111 112 113 114 115 116 117 118 119 120 ... 332 333

Comentarios a estos manuales

Sin comentarios