Administration Tasks : Configuring Log Settings

Configuring Log Settings
Use the Administration - Log-Settings page to configure local and remote logging parameters.
Each requires that you specify the minimum severity level of event to log.
n
Set up local logging in the Log Configuration section.
n
Set up remote logging by using the Log Facilities Configuration and Remote Log Receivers sections.
Minimum Severity Levels
In decreasing order of severity, the levels are as follows.
EMERGENCY
Includes all alarms the appliance generates: CRITICAL, MAJOR, MINOR, and WARNING
CRITICAL
ERROR
INFORMATIONAL
If you select NONE, then no events are logged.
n
n
If you select NOTICE (the default), then the log records any event with a severity of NOTICE, WARNING, ERROR, CRITICAL, ALERT, and EMERGENCY.
n
These are purely related to event logging levels, not alarm severities, even though some naming conventions overlap. Events and alarms have different sources. Alarms, once they clear, list as the ALERT level in the Event Log.
Configuring Remote Logging
n
n
A syslog server is independently configured for the minimum severity level that it will accept. Without reconfiguring, it may not accept as low a severity level as you are forwarding to it.
n
In the Log Facilities Configuration section, assign each message/event type (System / Audit / Flow) to a syslog facility level (local0 to local7).
You can use a different facility for each log, or you can select the same facility for all the logs.
n
For each remote syslog server that you add to receive the events, specify the receiver's IP address, along with the messages' minimum severity level and facility level.

Please send comments or suggestions regarding user documentation to techpubs@silver-peak.com.