I have about 100 polices on my device, some of them has "Log at Session Start" option enabled. Is it posisible to find it from the CLI ?
I have very little skills in CLI so please give me the whole CLI command.
I realised that my weekly reports are unusable because I have only data from last few days. How I can save some space on PA200 to get more logs than last 7 days?
Solved! Go to Solution.
Pre-requisite: Text-Editors like Notepad ++ or PSPad
Enable Logging for CLI session from the Terminal Application eg Putty.
> set cli pager off
> set cli config-output-format set
# show rulebase security
Open CLI session log and Find-All for the string "log-start yes"
Our you could just export whole configuration to XML file and search it.
Considering log size - look at what you are logging. Some chatty protocols (example: DNS) are not always worth logging, think about updates (adobe-update, ms-update) and so on.
Look into ACC, sorting by sessions, at applications. Search for those that you are willing to "sacrifice", disable logging for them.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!