Logging and reporting
You can configure the DFL-1000 NPG to record three types of logs:
•
Traffic logs record all traffic that attempts to connect through the DFL-1000 NPG.
•
Event logs record management and activity events.
You can also use Log & Report to configure the DFL-1000 NPG to send alert emails for:
•
Critical firewall or VPN events or violations (also recorded by the event log)
This chapter describes:
•
Configuring logging
•
Viewing event log saved to memory
•
Viewing and maintaining logs saved to the hard disk
•
Configuring alert email
•
Log message formats
Configuring logging
You can configure logging to record logs to one or more of:
•
a computer running a syslog server,
•
a computer running a WebTrends firewall reporting server,
•
the DFL-1000 hard disk (if your DFL-1000 NPG contains a hard disk),
•
the DFL-1000 system memory (if your DFL-1000 NPG does not contain a hard disk).
Logging to system memory is not available on all DFL-1000 models. The optional hard disk is not available for
all DFL-1000 models.
You can also configure the kind of information that is logged.
This section describes:
•
Recording logs on a remote computer
•
Recording logs on a NetIQ WebTrends server
•
Recording logs on the DFL-1000 hard disk
•
Logging event log to memory
•
Selecting what to log
Recording logs on a remote computer
Use the following procedure to configure the DFL-1000 to record log messages on a remote computer.
The remote computer must be configured with a syslog server.
•
Go to Log&Report > Log Setting .
•
Select Log to Remote Host to send the logs to a syslog server.
•
Enter the IP address of the remote computer running syslog server software.
•
Select Apply to save your log settings.
Recording logs on a NetIQ WebTrends server
Use the following procedure to configure the DFL-1000 to record logs on a remote NetIQ firewall reporting
server for storage and analysis. DFL-1000 log formats comply with WebTrends Enhanced Log Format
DFL-1000 User Manual
123
Need help?
Do you have a question about the DFL-1000 and is the answer not in the manual?