System Log Settings - McAfee MAP-3300-SWG - Web Security Appliance 3300 Product Manual

Product guide
Table of Contents

Advertisement

Access control list
Table 268 Option definitions
Option
Definition
Access control list The appliance is set to allow SNMP queries from all devices. We recommend that you
change the settings to allow access from known devices only. Specify the IP address
numbers of the devices that can read the appliance's MIB parameters.

System Log Settings

Use this page to specify standard or extended system logging and the events to be recorded in the
system log. You can also send logs to off-box servers.
System | Logging, Alerting and SNMP | System Log Settings
Syslog is a method for delivering log information across a network, usually via UDP port 514. The
syslog protocol and message format are defined in RFC 3164.
Extended logging creates a structured output log file using the syslog protocol. The extended logging
option provides name–value pairs for each logged event.
Table 269 Option definitions
Option
Definition
Enables system logging (syslog) information to be collected and delivered to the
Enable system
on-appliance logging system, or sent to an off-box solution.
log events
Select the type of logging format that you want to use. This option creates an output
log file that is structured so that it can be easily read by third-party applications and
used to generate custom reports. Due to the amount of data generated, we
recommend that this option is only enabled when using TCP syslog. Choose from:
• Original
• Splunk
• Arcsight
Conversation events and Aggregated data events are not reported in the extended
logging format.
Click View the system logs to see the log files on the appliance.
Specify the events to capture within the syslog. To prevent very large log files, we
Log events to
recommend that you record only events that you want to monitor closely, and deselect
the syslog for
the following
the events when you have finished.
event types:
The appliance cannot store the transport events produced by heavy traffic for long
periods. We recommend that you use the off-box syslog option to forward the
transport events to a central syslog server.
McAfee Email and Web Security Appliances 5.6.0 Product Guide
Overview of System features
Logging, Alerting and SNMP
269

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web security appliance 5.6.0

Table of Contents