Logs
What can I do here?
Use this window to see logs from all Security Gateways. The logs are stored on the Security Management Server and Log Servers.
|
Getting Here - Logs & Monitor > Open Log View
|
Log Analysis
SmartConsole lets you transform log data into security intelligence. Search results are fast and immediately show the log records you need. The Security Gateways send logs to the Log Servers on the Security Management Server or on a dedicated server. Logs show on the SmartConsole tab. You can:
- Quickly search through logs with simple Google-like searches.
- Select from many predefined search queries to find the applicable logs.
- Create your own queries using a powerful query language.
- Monitor logs from administrator activity and connections in real-time.
Enabling Log Indexing
Log indexing on the Security Management Server or Log Server reduces the time it takes to run a query on the logs. Log indexing is enabled by default.
In a standalone deployment, log indexing is disabled by default. Enable log indexing only if the standalone computer CPU has 4 or more cores.
To manually enable Log Indexing:
- Open SmartConsole.
- From the view, double-click the Security Management Server or Log Server object.
The window opens.
- In the tab, select .
- From the navigation tree, click .
- Select
- Click .
- Click .
- From , select .
Customizing the Results Pane
By default, SmartConsole shows a predefined set of columns and information based on the selected blade in your query. This is known as the . For example:
- The DLP column profile includes columns for: Blade, Type, DLP Incident UID, and severity.
- The Threat Prevention column profile includes columns for: Origin, Action, Severity, and Source User.
A column profile is assigned based on the blade that occurs most frequently in the query results. This is called , and is enabled by default.
The Column Profile defines which columns show in the and in which sequence. You can change the Column Profile as necessary for your environment.
To use the default Column Profile assignments:
- Right-click a column heading and select > .
To manually assign Column Profile assignments by default:
- Right-click a column heading and select > .
To manually assign a different Column Profile:
- Right-click a column heading and select .
- Select a Column Profile from the options menu.
To change a Column Profile:
- Right-click a column heading and select >
- In the window, select a Column Profile to change.
- Select fields to add from the column.
- Click .
- Select fields to remove from the column.
- Click .
- Select a field in the .
- Click or to change its position in the Pane.
- Double-click the Width column to change the default column width for the selected field.
- To change the column width, drag the right column border in the Pane.
- To save the column width, right-click and select .
The column is applicable to future sessions.
Viewing Rule Logs
You can search for the logs that are generated by a specific rule, from the Security Policy or from the Logs & Monitor > tab.
To see logs generated by a rule (from the Security Policy):
- In SmartConsole, go to the view.
- In the or , select a rule.
- In the bottom pane, click one of these tabs to see:
- - Rule name, rule action, rule creation information, and the hit count. Add custom information about the rule.
- (Access Control Policy only) - Details for each column. Select columns as necessary.
- - By default, shows the logs for the Current Rule. You can filter them by , , , , , , , ( is the default), , , or .
- (Access Control Policy only) - List of rule operations in chronological order, with the information about the rule type and the administrator that made the change.
To see logs generated by a rule (by Searching the Logs):
- In SmartConsole, go to the view.
- In the or , select a rule.
- Right-click the rule number and select .
- In the Logs & Monitor > tab, search for the logs in one of these ways:
- Paste the Rule UID into the query search bar and press Enter.
- For faster results, use this syntax in the query search bar:
layer_uuid_rule_uuid:*_<UID>
For example, paste this into the query search bar and press Enter:
layer_uuid_rule_uuid:*_46f0ee3b-026d-45b0-b7f0-5d71f6d8eb10