12 SonicOS-X - 7.0.1 - LogEvents - ReferenceGuide
12 SonicOS-X - 7.0.1 - LogEvents - ReferenceGuide
1
Log Events
Reference Guide
Contents 1
Introduction to SonicOS/X Log Events . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Logs > System Logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Log > Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Traffic Report Syslogs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Access Rules Logging Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Syslog Events . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Log > Syslog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Index of Syslog Tag Field Descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
Configuration Auditing Syslog Tags . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
Syslog Group Category (gcat) Values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Examples of Standard Syslog Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
Examples of ArcSight Syslog Messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107
Legacy Categories . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
Priority Levels . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
The Traffic Report Syslogs are generated only if those messages are enabled in the Log > Settings page with the
desired Frequency Filter Interval, normally 0, which means do not filter. They are always generated on
Connection Closed events.
The Connection Closed event is represented by two different messages, id=97 and id=537. The Syslog Website
Accessed (97) contains URL data while Connection Closed (537) does not.
On the Log > Settings page, expand the item in the Category column to display the group names and then
expand the group to display the events in that group. For example, expand Log, then expand Syslog to display
the Syslog Website Accessed event.
Edit Button
You can then view or enable/disable the Report Events via Syslog option and configure its Frequency Filter
Interval. A value of zero for the Frequency Filter Interval means to log every event (no filtering).
NOTE: The Logging option is only available on firewalls running SonicOS (Classic mode), but not on
firewalls running SonicOSX (Policy mode).
The associated policy log events are listed in the Policy Logs Controlled by Enable Logging Option in Access Rules
table.
Syslog Tags
For example, gcat=3 means “Security Services” category, and gcat=6 means “Network” category in the following
examples:
Legacy Categories
This section can be used as a reference for understanding different categories and their descriptions. The
following table describes the Legacy categories shared in all SonicOS/X releases.
Priority Levels
The following table displays the Priority Number and Priority Name for Syslog tags. The value here corresponds
to the Priority Level column of the Log Event Message Index table, or the pri tag in the Syslog Tags table. For
example, a tag with “pri=0” means Emergency Priority.
Priority Level
CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if instructions are not followed.
IMPORTANT, NOTE, TIP, MOBILE, or VIDEO: An information icon indicates supporting information.