485
Monitoring the security gateway
Monitoring IDS/IPS alerts
Related Information
For further information related to this topic, see the following:
■
Performing an advanced IDS/IPS alert search
You can use the Advanced tab of the Log Search dialog box to apply more advanced search criteria.
This lets you perform a more granular search than the basic search, using criteria such as specific log
levels, specific message parameters, and so on.
The search is additive. The only messages that are displayed are those that meet all search criteria.
Note:
An advanced search of a large log file can impact performance.
You can search the log file and limit the display of IDS/IPS alerts based on the following criteria:
■
Event Types
■
Parameters
■
System names
■
Process IDs
■
Messages numbers
■
Text patterns
Prerequisites
None.
To configure an advanced IDS/IPS alert log filter
1
In the SGMI, in the left pane, under Monitors, click
Logs
.
2
In the right pane, on bottom of the IDS/IPS Alerts tab, click
Search
.
3
In the Log Search window, on the Advanced tab, click
Event Types.
4
To display only alerts with specific event types, check each type of event you want to display.
To display all event types, click
Select All
.
To uncheck all event types, click
Clear
.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...