
Logging and reporting
You can configure the DFL-500 to record 3 types of logs:
·
Traffic logs record all traffic that attempts to connect through the DFL-500
·
Event logs record changes to the system configuration
·
Attack logs record attacks intercepted by the NIDS
This chapter describes:
·
·
Configuring logging
You can configure logging to record logs to one or more of the following locations:
·
A computer running a syslog server
·
A computer running a WebTrends firewall reporting server
You can also configure the kind of information that is logged.
·
Recording logs on a remote computer
·
Recording logs on a WebTrends server
·
Recording logs on a remote computer
Use the following procedure to configure the DFL-500 to record logs onto a remote computer. The remote
computer must be configured with a syslog server.
·
Go to
Log&Report > Log setting
.
·
Select Log to Remote Host to send the logs to a syslog server.
·
Add the IP address of the computer running syslog server software.
·
Select Apply to save your log settings.
Recording logs on a WebTrends server
Use the following procedure to configure the DFL-500 to record logs onto a remote WebTrends firewall
reporting server for storage and analysis. DFL-500 log formats comply with WebTrends Enhanced Log
Format (WELF) and are compatible with WebTrends Firewall Suite 4.1. Refer to the WebTrends Firewall
Suite documentation for more information.
To record logs on a WebTrends server:
·
Go to
Log&Report > Log setting
.
·
Select Log to WebTrends.
·
Add the IP address of the WebTrends firewall reporting server.
·
Select Apply to save your log settings.
DFL-500 User Manual
103