Print Download PDF Send Feedback

Previous

Next

Log Analysis

SmartConsole lets you transform log data into security intelligence. Search results are fast and immediately show the log records you need. The Security Gateways send logs to the Log Servers on the Security Management Server or on a dedicated server. Logs show on the SmartConsole Logs & Monitor Logs tab. You can:

Configuring Logging

To configure logging from a Security Gateway to a Security Management Server or a Log Server:

  1. Define one or more Log Servers (if necessary).
  2. Enable logging on the Security Management Server and the Log Servers.
  3. Configure the Security Gateways to send logs to the Log Servers.
  4. Install the Policy.

To enable logging on a server:

  1. In SmartConsole, go to Gateways & Servers and double-click the server object.

    The properties window opens.

  2. Establish Secure Internal Communication between the Security Management Server and the Log Server. Make the certificate state: Trust Established.
  3. In the Management tab, select Logging & Status.
  4. From the navigation tree, click Logs.

    This shows the Security Gateways that forward logs to this machine.

  5. Make sure that Enable Log Indexing is selected. It is enabled by default optimizes the log search time.
  6. Click OK.

To configure a Security Gateway to send logs to log servers:

  1. In SmartConsole, go to Gateways & Servers and double-click the gateway object.

    The gateway properties window opens.

  2. From the navigation tree, click Logs.
  3. In the Send gateway logs and alerts to server section, click the plus sign and select a server.

    Make sure that in the Type column, Send Logs and Alerts is selected.

  4. Optional - In the In case one of the above log servers is unreachable, send logs to, add backup servers.

To complete the configuration:

  1. Click Publish.
  2. Install the Access Control Policy.