Using Snmp Required And Optional Format-Specific Filters; Viewing Snmp Format Output; Exporting To E-Mail - Juniper NETWORK AND SECURITY MANAGER 2010.2 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

SNMP
--community
--server
Copyright © 2010, Juniper Networks, Inc.

Using SNMP Required and Optional Format-Specific Filters

You can use the following required format-specific filters for exporting to SNMP:
Multiple
Required
No
Yes
No
Yes
The SNMP format has no optional format-specific filters.

Viewing SNMP Format Output

SNMP trap log entries use the following format:
<day id> <record id> <time received> <time generated> <device domain> <device
domain version> <device> <device ip> <category> <subcategory> <source zone> <source
interface> <source ip> <source port> <nat src ip> <nat src port> <destination
zone> <destination interface> <destination ip> <destination port> <nat dst ip>
<nat dst port> <protocol> <rule domain> <rule domain version> <policy> <rulebase>
<rulenumber> <action> <severity> <isalert> <details> <user str> <application
str> <uri str> <elapsed secs> <bytes in> <bytes out> <bytes total> <packets in>
<packets out> <packets total> <repeat count> <has packet data> <var data enum>
<application name> <device family> <policy id> <var data>
To send log records to the public SNMP server at 192.168.1.15, use the --public and --server
options:
sh devSvrCli.sh --log2action --action --snmp --community public --server 192.168.1.15

Exporting to E-mail

The e-mail action directs the system to output logs for an e-mail address in SMTP format.
You must specify the recipient's e-mail address the exported log records, andand you
have the option of specifying the sender's email address.
To export:
Login to the Device Server as root, then change to the utility directory by typing: cd
1.
/usr/netscreen/DevSvr/utils.
To export to a file, type:
2.
sh devSvrCli.sh --log2action --action --email <sender> <recipient>
The Device Server exports all log records to the specified e-mail address for the recipient.
Meaning
Specify SNMP community string. The
community is an arbitrary string that the SNMP
server is configured to recognize. For details on
the community parameter, refer to section 3.2.5
of RFC 1098.
You might need to ask your SNMP server
administrator for the server community string.
Specify SNMP manager IP address
The value must be encoded as
[IP|FQDN:<port>]
Chapter 18: Logging
779

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.2

Table of Contents