30
©
SOLIDA SYSTEMS INTERNATIONAL
2016
11. Data Logging
The appliances have a wide selection of logging options. The factory default is to log all rule events
as well as all dropped network packets but the user has the option to enable further logging,
including full packet capture.
Network packet data is written to the log files in the industry standard PCAP format. This makes it
possible to use tools such as Wireshark to open these files, and perform analysis on the packet
content.
11.1 Packet Logging
Packet logging will log every single packet passing through the appliance. This mode is typically
only used during troubleshooting of the network. The resulting log files can become very large so
it is important to select an appropriate rollover option to avoid filling up the disk space in the
appliance. Packet logging should be disabled during normal usage.
11.2 Dropped Packet Logging
This option will log all network packets that are dropped by the appliance. Packets will be dropped
by the rule engine as well as by the reputation detection engine. This logging option is enabled by
default. These log files can be used during forensic analysis to determine the exact reason a packet
was dropped.
11.3 Event Logging
Event logging is enabled by default and it is strongly recommended to always keep it enabled. The
resulting log files contain information about all events occurring in the appliance. The default
settings are as shown in the picture below:
Figure 11.1 Event logging configuration window.