Log Receivers; Syslog Receiver - D-Link DFL-1600 User Manual

Network security firewall
Hide thumbs Also See for DFL-1600:
Table of Contents

Advertisement

28
HA
– High Availability events.
IDS/IDSUPDATE
– Intrusion Detection events and database update.
ZONEDEFENSE
– ZoneDefense events.
SNMP
– allowed and disallowed SNMP accesses.
IP.../TCP...
– information concerning TCP/IP packets.
5.2

Log Receivers

A log receiver is a separate computer, know as "Syslog server", or a
memory section built in the firewall to handle all the logged events
generated by the firewall.
Once a new event is received, the receiver adds an entry into the log file to
record the data.
5.2.1

Syslog Receiver

D-Link Firewall can send log data to syslog recipients. Syslog is a
standardized protocol for sending log data to loghosts, although there is no
standardized format of these log messages. The format used by D-Link
Firewall is well suited for automated processing, filtering and searching.
Although the exact format of each log entry depends on how a particular
syslog recipient works, most are very much alike. The way in which logs are
read is also recipient dependent. Syslog daemons on UNIX servers usually
log to text files, line by line.
Most syslog recipients preface each log entry with a timestamp and the IP
address of the machine that sent the log data:
Feb 5 2000 09:45:23 gateway.ourcompany.com
This is followed by the text the sender has chosen to send. All log entries
from D-Link Firewall are prefaced with "FW:" and a category, e.g.
"DROP:".
D-Link Firewalls User's Guide
Chapter 5. Logging

Advertisement

Table of Contents
loading

Table of Contents