Skybox Appliance 8000 Quick Start Guide
Skybox version 10.1.200
30
›
CHANGE_LOGS_OLD="/var/log/firewall_assurance/change_logs_old"
(archive directory)
›
LOG_RETENTION=2
(days to keep logs)
›
ARCHIVE_RETENTION=3
(days to keep archives after they are saved in the
archive directory)
What are the log files named?
A separate log is generated for each device. Log file names have the format:
•
(New logs)
<device name | IP address>_<time of creation>.log
•
(Archived logs)
<device name | IP address>_<time of creation>.zip
How can the logs be imported into Skybox?
Device logs can be imported using the following tasks, depending on the
information that you are looking for:
›
Change Tracking Events – Syslog Import
›
Traffic Events – Syslog Import
At a minimum, you need the following information (in the task) to import the
logs:
›
In the Basic tab:
•
The directory path of the files (
/var/log/syslog-ng/new
and
/var/log/firewall_assurance/change_logs/new
)
•
Modules: The scope of devices whose logs are to be imported
›
In the Advanced tab:
•
The date format used by the device
•
(For Cisco and Juniper traffic events) The positions of the Device ID and
date in the log