Local storage tab
Log configuration makes it possible to allocate disk space for each log category on the firewall. In this menu, logging on the firewall can be enabled or disabled.
|
Enables or disables logging on the firewall. Logging is disabled by default if the firewall does not have a storage device. |
NOTE
When logging to a local device is disabled, a real-time logging mechanism takes over.
These logs can then be accessed in Monitoring > Logs - Audit logs > Real-time logs.
Storage device
| Storage device | Select the storage device on which logs will be saved:
NOTE |
| Refresh | Refreshes the list of available storage media. |
| Format | Formats the selected storage medium. |
NOTE
In a high availability configuration, actions relating to the SD card are only valid for the card inserted into the active firewall. To use an SD card on the passive firewall, you must first switch from passive to active mode in the Maintenance module.
Configuring the space reserved for logs
There are several categories under which the firewall logs events detected by log functions, including data relating to capture features.
All categories share the same storage space. You can enable or disable logging for a particular category and modify its disk space quota by assigning a percentage to it.
Rule grid
| Enabled |
Shows that logging is enabled for a particular log category. Double-click to change the status. |
| Category | Specifies the name of the log category or family. |
| % |
Shows the percentage of disk space assigned to the log family. Double-click to edit. The total disk space reserved for all log categories is shown at the bottom of the grid: a warning message will appear if it exceeds 100%. However, changes are allowed. If a storage device is full, the most recent logs erase the oldest logs. |
| Size |
Shows the disk space that is assigned to each log category on the storage device. This value varies according to the percentage assigned. |
The Enable all or Disable all buttons make it possible to enable or disable logging in a single action for all log categories.
Confirm changes by clicking on Apply.
You must save your changes if the total disk space reserved exceeds 100%.
Log categories
| Administration (serverd) | Events relating to the firewall administration server (serverd). |
| Authentication | Events relating to user authentication. |
| Network connections | Events relating to connections allowed through and to the firewall. The log is written when the connection ends. |
| System events | Events directly relating to the system: shutdown and startup of the firewall, system error, etc. Shutting down and starting log functions correspond to shutting down and starting the daemons that generate logs. |
| Alarms | Events relating to the application of intrusion prevention features. |
| HTTP proxy | Events relating to HTTP traffic. |
| Application connections (plugin) | Events relating to processes carried out by ASQ plugins. |
| SMTP proxy | Events relating to SMTP traffic. |
| Filter policy | Events relating to the application of filter functions. |
| IPsec VPN | Events relating to the setup of SAs. |
| SSL VPN | Events relating to setup of the SSL VPN. |
| POP3 proxy | Events relating to message sending. |
| Statistics | Events relating to real-time monitoring. |
| FTP proxy | Events relating to FTP traffic. |
| SSL proxy | Events relating to SSL traffic. |
| Sandboxing | Events relating to file sandboxing if the subscription for this option has been activated. |
| Network captures | Data obtained from network captures activated on the firewall. |
| Router statistics | Data obtained from statistics of routers and their gateways. |
| Dynamic multicast routing | Events relating to dynamic multicast routing. |
| Routing | Events relating to unicast routing (static routing and dynamic routing [BIRD]). |
| REST API |