Log>Automation - SonicWALL SonicOS Enhanced 2.2 Administrator's Manual

Sonicwall internet security appliance
Table of Contents

Advertisement

Log>Automation
Click Log, and then Automation to begin configuring the SonicWALL to send log files using
e-mail and configuring syslog servers on your network.
E-mail
The E-Mail section includes settings that allow you to specify the handling of e-mail alerts and the sending
of log files.
Mail Server - to e-mail log or alert messages, type the name or IP address of your mail server in the
Mail Server field. If this field is left blank, log and alert messages are not
e-mailed.
Send Log To - type your full e-mail address in the Send log to field to receive the event log via e-
mail. Once sent, the log is cleared from the SonicWALL memory. If this field is left blank, the log is
not e-mailed.
Send Alerts To - type your full e-mail address (username@mydomain.com) in the Send alerts to
field to be immediately e-mailed when attacks or system errors occur. Type a standard e-mail address
or an e-mail paging service. If this field is left blank, e-mail alert messages are not sent.
Send Log / Every / At - The Send Log menu determines the frequency of log e-mail messages: Dai-
ly, Weekly, or When Full. If the Weekly or Daily option is selected, then select the day of the week
the e-mail is sent in the Every menu. If the Weekly or the Daily option is selected, type the time of
day when the e-mail is sent in the At field.
Syslog Servers
In addition to the standard event log, the SonicWALL can send a detailed log to an external Syslog server.
The SonicWALL Syslog captures all log activity and includes every connection source and destination IP
address, IP service, and number of bytes transferred. The SonicWALL Syslog support requires an
external server running a Syslog daemon on UDP Port 514. Syslog Analyzers such as SonicWALL
ViewPoint or WebTrends Firewall Suite can be used to sort, analyze, and graph the Syslog data.
Messages from the SonicWALL are then sent to the server(s). Up to three Syslog server IP addresses
can be added.
The following are global Syslog Server settings:
Syslog Event Redundancy (seconds) - This setting prevents repetitive messages from being writ-
ten to Syslog. If duplicate events occur during the period specified in the Syslog Event Redundancy
Log Page 163

Advertisement

Table of Contents
loading

Table of Contents