data:image/s3,"s3://crabby-images/21729/217291a1165aeaa5e0806f4d6218f3181581dc09" alt="FireBrick FB6402 Скачать руководство пользователя страница 48"
Event Logging
31
The module name refers to which part of the system caused the log entry, and is also shown in all other types
of logging such as web and console.
To enable log messages to be sent to a syslog server, you need to create a
syslog
object that is a child of the
log target (
log
) object. You must then specify the DNS name or IP address of your syslog server by setting
the
server
attribute on the
syslog
object. You can also set the facility and/or severity values using these
attributes :-
•
facility
: the 'facility' to be used in the syslog messages - when syslog entries are generated by subsystems
or processes in a general-purpose operating system, the facility typically identifies the message source ;
where the commonly used facility identifiers are not suitable, the "local0" thru "local7" identifiers can be
used. If the
facility
attribute is not set, it defaults to
LOCAL0
•
severity
: the severity value to be used in the syslog messages - if not set, the severity defaults to
NOTICE
The FB6000 normally uses the 'standard' syslog port number of 514, but if necessary, you can change this by
setting the
port
attribute value.
5.3.2. Email
You can cause logs to be sent by e-mail by creating an
object that is a child of the log target (
log
) object.
An important aspect of emailed logs is that they have a delay and a hold-off. The delay means that the email
is not sent immediately because often a cluster of events happen over a short period and it is sensible to wait
for several log lines for an event before e-mailing.
The hold-off period is the time that the FB6000 waits after sending an e-mail, before sending another. Having
a hold-off period means you don't get an excessive number of e-mails ; since the logging system is initially
storing event messages in RAM, the e-mail that is sent after the hold-off period will contain any messages that
were generated during the hold-off period.
The following aspects of the e-mail process can be configured :-
• subject : you can either specify the subject, by setting the
subject
attribute value, or you can allow the
FB6000 to create a subject based on the first line of the log message
• e-mail addresses : as to be expected, you must specify a target e-mail address, using the
to
attribute. You
can optionally specify a From: address, by setting the
from
atttribute, or you can allow the FB6000 to create
an address based on the unit's serial number
• outgoing mail server : the FB6000 normally sends e-mail directly to the Mail eXchanger (MX) host for the
domain, but you can optionally specify an outgoing mail server ('smart host') to use instead, by setting the
server
attribute
• SMTP port number : the FB6000 defaults to using TCP port 25 to perform the SMTP mail transfer, but if
necessary you can set the
port
attribute to specify which port number to use
• retry delay : if an attempt to send the e-mail fails, the FB6000 will wait before re-trying ; the default wait
period is 10 minutes, but you can change this by setting the
retry
attribute
An example of a simple log target with e-mailing is available in a factory reset configuration - the associated
XML is shown below, from which you can see that in many cases, you only need to specify the
to
attribute
(the
comment
attribute is an optional, general comment field) :-
<log name="fb-support"
comment="Log target for sending logs to FireBrick support team">
<email to="[email protected]"
comment="Crash logs emailed to FireBrick Support team"/>
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......