Skybox Appliance 7000 Quick Start Guide
Skybox version 11.7.100
29
What are the syslog folder names?
Since an installation may have multiple firewalls from various vendors, the syslogs are stored
in folders per vendor, as described in this table.
Syslogs from vendors that do not have a specific folder are stored in /var/log/syslog-ng/new.
VENDOR
SYSLOG FOLDER
Checkpoint
/var/log/syslog-ng/new/cp
Cisco
/var/log/syslog-ng/new/cisco
Forcepoint/Stonegate
/var/log/syslog-ng/new/fpoint
Palo Alto
/var/log/syslog-ng/new/pa
McAfee
/var/log/syslog-ng/new/mcf
FirePower
/var/log/syslog-ng/new/fmc
Junos/Juniper
/var/log/syslog-ng/new/junos
Fortigate
/var/log/syslog-ng/new/fg
All others
/var/log/syslog-ng/new
What are the log files named?
A separate log is generated for each device. Log file names have the format:
l
(New logs)
<device name | IP address>_<time of creation>.log
l
(Archived logs)
<device name | IP address>_<time of creation>.zip
How can the logs be imported into the Skybox model?
Device logs can be imported using the following tasks:
l
Change Tracking Events – Syslog Import
l
Traffic Events – Syslog Import
To import the logs, you must include:
l
In the Basic tab:
o
The directory path of the files (
/var/log/syslog-ng/new
and
/var/log/firewall_
assurance/change_logs/new
)
o
Modules: The scope of devices whose logs are imported
l
In the Advanced tab:
o
The date format used by the device
o
(For Cisco and Juniper traffic events) The positions of the Device ID and date in the log