SonicWall Monitor Logs User Manual

SonicOS and SonicOSX 7 Monitor Logs
Administration Guide
Contents
System Logs 3
Viewing System Logs 3
System Log Functions 4
Display Options 5
Filtering the View 8
Auditing Logs 9
What is Configuration Auditing 9
Benefits of Configuration Auditing 9
What Information is Recorded 10
What Information is Not Recorded 10
Audit Recording in High Availability Configurations 10
Modifying and Supplementing Configuration Auditing 11
SNMP Trap Control 11 E-CLI Commands 11
Auditing Record Storage and Persistence 11
Managing the Audit Logs Table 12
Viewing Auditing Logs 12 Manually Emailing Auditing Logs 12 Exporting Auditing Logs 13 Refreshing the Auditing Logs 13 Displaying the Auditing Logs on the console 13 Auditing All Parameters During Addition 14
SonicWall Support 15
About This Document 16
SonicOS/X 7 Monitor Logs Administration Guide
2

System Logs

NOTE: References to SonicOS/X indicate that the functionality is available in both SonicOS and
SonicOSX.
The SonicWall network security appliance maintains an Event log for tracking potential security threats.
Topics:
l Viewing System Logs l System Log Functions l Display Options l Filtering the View
1

Viewing System Logs

To view system events, navigate to Monitor > Logs > System Logs page.
For a description of the:
l Functions, see System Log Functions
l Columns, see Display Options
SonicOS/X 7 Monitor Logs Administration Guide
System Logs
3

System Log Functions

The System Log table provides numerous settings to allow you to navigate, view, and export results. Table columns can be customized, so that you can view full data on any event, or only the data you need. Table entries can be sorted to display in either ascending or descending order.
To sort the entries in the Event Log, click the column heading. The entries are sorted by ascending or descending order. The arrow to the right of the column name indicates the sorting status. A down arrow means ascending order. An up arrow indicates a descending order.
The top row of the Event Log contains various functions. Functions pertaining only to Event Logs are described in the below table.
SYSTEM EVENT LOG FUNCTIONS
Option Function Action
Search The Event Log displays the log entries that
match the search string.
Show Select the interval for the Event Log. The
event logs from that period are displayed:
l Last 60 seconds l Last 2 minutes l Last 5 minutes (default) l Last 10 minutes l Last 15 minutes l Last 30 minutes l Last 60 minutes l Last 3 hours l Last 6 hours l Last 12 hours l Last 24 hours l Last 7 days l Last 15 days l Last 30 days l All entries
Refresh Click to refresh the system log data.
Configure Log Click this link and you are navigated to
Device > Log > Settings to configure the items which needs to be tracked in the Event Log.
Clear Logs Click to clear the logs from the table.
Export Click to export the logs in CSV, TXT files,
and email
SonicOS/X 7 Monitor Logs Administration Guide
System Logs
4

Display Options

Customize the Events log to display as many or few columns that meet your needs.
To select which columns to display:
1.
Navigate to Monitor > Logs > System Logs.
2.
Click Grid Settings icon . The Grid Settings dialog displays:
3.
Select the items you want to appear as columns in the System Log.
General General information about the log event.
Time Local date and time the event occurred.
IMPORTANT: This option is selected
by default. It is dimmed, and cannot be deselected.
ID Identifying number for the event.
IMPORTANT: This option is selected
by default. It is dimmed, and cannot be deselected.
Category Category of the event. This option is
selected by default.
Group Group designation of the event.
Event Name of the event.
Msg Type Type of message; usually Standard
Message String.
Priority Priority level of the event, such as Inform
(information) or Error.
IMPORTANT: This option is selected
by default.
Message Information about the event.
SonicOS/X 7 Monitor Logs Administration Guide
System Logs
5
Loading...
+ 11 hidden pages