Local storage tab

Log configuration makes it possible to allocate disk space for each log category on the firewall. In this menu, logging on the firewall can be enabled or disabled.


Enables or disables logging on the firewall.

Logging is disabled by default if the firewall does not have a storage device.

NOTE
When logging to a local device is disabled, a real-time logging mechanism takes over.
These logs can then be accessed in Monitoring > Logs - Audit logs > Real-time logs.

Storage device

Storage device Select the storage device on which logs will be saved:
  • Firewall’s internal storage medium,
  • SD card for firewalls are equipped with an external storage medium.

NOTE
For more information, refer to the SNS Presentation and installation guide, under Appendix B: log storage.

Refresh Refreshes the list of available storage media.
Format Formats the selected storage medium.

NOTE
In a high availability configuration, actions relating to the SD card are only valid for the card inserted into the active firewall. To use an SD card on the passive firewall, you must first switch from passive to active mode in the Maintenance module.

Configuring the space reserved for logs

There are several categories under which the firewall logs events detected by log functions, including data relating to capture features.

All categories share the same storage space. You can enable or disable logging for a particular category and modify its disk space quota by assigning a percentage to it.

Rule grid

Enabled

Shows that logging is enabled for a particular log category.

Double-click to change the status.

Category Specifies the name of the log category or family.
%

Shows the percentage of disk space assigned to the log family.

Double-click to edit.

The total disk space reserved for all log categories is shown at the bottom of the grid: a warning message will appear if it exceeds 100%.

However, changes are allowed.

If a storage device is full, the most recent logs erase the oldest logs.

Size

Shows the disk space that is assigned to each log category on the storage device.

This value varies according to the percentage assigned.

The Enable all or Disable all buttons make it possible to enable or disable logging in a single action for all log categories.

Confirm changes by clicking on Apply.
You must save your changes if the total disk space reserved exceeds 100%.

Log categories

Administration (serverd) Events relating to the firewall administration server (serverd).
Authentication Events relating to user authentication.
Network connections Events relating to connections allowed through and to the firewall. The log is written when the connection ends.
System events Events directly relating to the system: shutdown and startup of the firewall, system error, etc. Shutting down and starting log functions correspond to shutting down and starting the daemons that generate logs.
Alarms Events relating to the application of intrusion prevention features.
HTTP proxy Events relating to HTTP traffic.
Application connections (plugin) Events relating to processes carried out by ASQ plugins.
SMTP proxy Events relating to SMTP traffic.
Filter policy Events relating to the application of filter functions.
IPsec VPN Events relating to the setup of SAs.
SSL VPN Events relating to setup of the SSL VPN.
POP3 proxy Events relating to message sending.
Statistics Events relating to real-time monitoring.
FTP proxy Events relating to FTP traffic.
SSL proxy Events relating to SSL traffic.
Sandboxing Events relating to file sandboxing if the subscription for this option has been activated.
Network captures Data obtained from network captures activated on the firewall.
Router statistics Data obtained from statistics of routers and their gateways.
Dynamic multicast routing Events relating to dynamic multicast routing.
Routing Events relating to unicast routing (static routing and dynamic routing [BIRD]).
REST API