Chapter 25 Logs Screens
ZyWALL 2 Plus User’s Guide
445
25.6 Syslog Logs
There are two types of syslog: event logs and traffic logs. The device generates an event log
when a system event occurs, for example, when a user logs in or the device is under attack.
The device generates a traffic log when a "session" is terminated. A traffic log summarizes the
session's type, when it started and stopped the amount of traffic that was sent and received and
so on. An external log analyzer can reconstruct and analyze the traffic flowing through the
device after collecting the traffic logs.
Table 158
Syslog Logs
LOG MESSAGE
DESCRIPTION
Event Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
msg="<msg>" note="<note>"
devID="<mac address>"
cat="<category>"
This message is sent by the system ("RAS" displays as the
system name if you haven’t configured one) when the
router generates a syslog. The facility is defined in the web
MAIN MENU
,
LOGS
,
Log Settings
page. The severity is
the log’s syslog class. The definition of messages and
notes are defined in the other log tables. The “devID” is the
MAC address of the router’s LAN port. The “cat” is the
same as the category in the router’s logs.
Traffic Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
msg="Traffic Log"
note="Traffic Log" devID="<mac
address>" cat="Traffic Log"
duration=seconds
sent=sentBytes
rcvd=receiveBytes
dir="<from:to>"
protoID=IPProtocolID
proto="serviceName"
trans="IPSec/Normal"
This message is sent by the device when the connection
(session) is closed. The facility is defined in the Log
Settings screen. The severity is the traffic log type. The
message and note always display "Traffic Log". The "proto"
field lists the service name. The "dir" field lists the incoming
and outgoing interfaces ("LAN:LAN", "LAN:WAN",
"LAN:DMZ", "LAN:DEV" for example).
Event Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
ob="<0|1>" ob_mac="<mac
address>" msg="<msg>"
note="<note>" devID="<mac
address>" cat="<category>"
This message is sent by the device ("RAS" displays as the
system name if you haven’t configured one) at the time
when this syslog is generated. The facility is defined in the
web
MAIN MENU
,
LOGS
,
Log Settings
page. The
severity is the log’s syslog class. The definition of
messages and notes are defined in the other log tables. OB
is the Out Break flag and the mac address of the Out Break
PC.
Event Log: <Facility*8 +
Severity>Mon dd hr:mm:ss
hostname src="<srcIP:srcPort>"
dst="<dstIP:dstPort>"
ob="0|1" ob_mac="<mac
address>" msg="<msg>"
note="<note>" devID="<mac
address>" cat="Anti Virus"
encode="< uu | b64 >"
This message is sent by the device ("RAS" displays as the
system name if you haven’t configured one) at the time
when this syslog is generated. The facility is defined in the
web
MAIN MENU
,
LOGS
,
Log Settings
page. The
severity is the log’s syslog class. The "encode" message
indicates the mail attachments encoding method. The
definition of messages and notes are defined in the Anti-
Virus log descriptions.
Содержание ADSL 2+ Security Gateway
Страница 1: ...www zyxel com ZyWALL 2 Plus Internet Security Appliance User s Guide Version 4 03 12 2007 Edition 1 ...
Страница 2: ......
Страница 25: ...Table of Contents ZyWALL 2 Plus User s Guide 25 Index 679 ...
Страница 26: ...Table of Contents ZyWALL 2 Plus User s Guide 26 ...
Страница 46: ...46 ...
Страница 88: ...Chapter 3 Wizard Setup ZyWALL 2 Plus User s Guide 88 ...
Страница 131: ...131 PART II Network LAN Screens 133 Bridge Screens 145 WAN Screens 151 DMZ Screens 171 Wireless LAN 181 ...
Страница 132: ...132 ...
Страница 144: ...Chapter 6 LAN Screens ZyWALL 2 Plus User s Guide 144 ...
Страница 180: ...Chapter 9 DMZ Screens ZyWALL 2 Plus User s Guide 180 ...
Страница 190: ...190 ...
Страница 209: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 209 Figure 138 SECURITY FIREWALL Rule Summary Edit ...
Страница 221: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 221 Figure 149 My Service Firewall Rule Example Rule Summary Completed ...
Страница 222: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 222 ...
Страница 252: ...Chapter 13 Content Filtering Reports ZyWALL 2 Plus User s Guide 252 ...
Страница 265: ...Chapter 14 IPSec VPN ZyWALL 2 Plus User s Guide 265 Figure 178 SECURITY VPN VPN Rules IKE Edit Gateway Policy ...
Страница 274: ...Chapter 14 IPSec VPN ZyWALL 2 Plus User s Guide 274 Figure 181 SECURITY VPN VPN Rules IKE Edit Network Policy ...
Страница 306: ...Chapter 15 Certificates ZyWALL 2 Plus User s Guide 306 Figure 203 SECURITY CERTIFICATES My Certificates Create Basic ...
Страница 328: ...Chapter 16 Authentication Server ZyWALL 2 Plus User s Guide 328 ...
Страница 330: ...330 ...
Страница 346: ...Chapter 17 Network Address Translation NAT ZyWALL 2 Plus User s Guide 346 ...
Страница 350: ...Chapter 18 Static Route ZyWALL 2 Plus User s Guide 350 ...
Страница 398: ...Chapter 21 Remote Management ZyWALL 2 Plus User s Guide 398 ...
Страница 416: ...Chapter 24 ALG Screen ZyWALL 2 Plus User s Guide 416 ...
Страница 417: ...417 PART V Logs and Maintenance Logs Screens 419 Maintenance 447 ...
Страница 418: ...418 ...
Страница 423: ...Chapter 25 Logs Screens ZyWALL 2 Plus User s Guide 423 Figure 274 LOGS Log Settings ...
Страница 466: ...466 ...
Страница 474: ...Chapter 27 Introducing the SMT ZyWALL 2 Plus User s Guide 474 ...
Страница 496: ...Chapter 30 LAN Setup ZyWALL 2 Plus User s Guide 496 ...
Страница 504: ...Chapter 32 DMZ Setup ZyWALL 2 Plus User s Guide 504 ...
Страница 508: ...Chapter 33 Wireless Setup ZyWALL 2 Plus User s Guide 508 ...
Страница 556: ...Chapter 38 Filter Configuration ZyWALL 2 Plus User s Guide 556 ...
Страница 570: ...Chapter 40 System Information Diagnosis ZyWALL 2 Plus User s Guide 570 ...
Страница 586: ...Chapter 41 Firmware and Configuration File Maintenance ZyWALL 2 Plus User s Guide 586 ...
Страница 594: ...Chapter 42 System Maintenance Menus 8 to 10 ZyWALL 2 Plus User s Guide 594 ...
Страница 598: ...Chapter 43 Remote Management ZyWALL 2 Plus User s Guide 598 ...
Страница 603: ...603 PART VII Troubleshooting and Specifications Troubleshooting 605 Product Specifications 613 ...
Страница 604: ...604 ...
Страница 612: ...Chapter 45 Troubleshooting ZyWALL 2 Plus User s Guide 612 ...
Страница 620: ...620 ...
Страница 644: ...Appendix B Pop up Windows JavaScripts and Java Permissions ZyWALL 2 Plus User s Guide 644 ...
Страница 668: ...Appendix E Importing Certificates ZyWALL 2 Plus User s Guide 668 ...
Страница 672: ...Appendix F Legal Information ZyWALL 2 Plus User s Guide 672 ...
Страница 678: ...Appendix G Customer Support ZyWALL 2 Plus User s Guide 678 ...