- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-01-2020 06:31 AM
Hello team,
We are sending all the traffic logs to our inhouse syslog servers. So whatever traffic is matching current security policies, all such traffic logs are forwarded to syslog server. Now in those logs, i am seeing everything like Source, Destination, port everything. Now our requirement, we need to send only specific logs to syslog for specific traffic. e.g. dont want to disclose source IP. How can i configure this?
Pls suggest.
04-01-2020 06:50 AM
I think you are looking for FILTER BUILDER under Log Forwarding Profiles. By default, it select 'All Logs' under Filter. But you can create custom filter as per your requirement. PFB snap for your ref. Once you create Filter, attach that Log Forwarding Profile to required security policies.
Hope it helps!
Mayur
04-01-2020 06:56 AM - edited 04-01-2020 07:00 AM
Hi @johnde ,
What @SutareMayur mentions will work and is very granular.
If you want to customize for your syslog-server you can also do this:
Goto your syslog server profile on the Device tab. There's a Custom Log Format tab ... click the Traffic one :
Add the field you want :
Hope this helps,
Kiwi.
04-01-2020 06:50 AM
I think you are looking for FILTER BUILDER under Log Forwarding Profiles. By default, it select 'All Logs' under Filter. But you can create custom filter as per your requirement. PFB snap for your ref. Once you create Filter, attach that Log Forwarding Profile to required security policies.
Hope it helps!
Mayur
04-01-2020 06:56 AM - edited 04-01-2020 07:00 AM
Hi @johnde ,
What @SutareMayur mentions will work and is very granular.
If you want to customize for your syslog-server you can also do this:
Goto your syslog server profile on the Device tab. There's a Custom Log Format tab ... click the Traffic one :
Add the field you want :
Hope this helps,
Kiwi.
04-01-2020 09:15 AM
Yes, this is very helpful when you have multiple syslog servers and you want to filter specific logs fields for specific syslog server only.
@kiwiThanks for sharing this too.
Mayur
04-02-2020 03:35 AM
Thanks for all your suggestions and inputs. I did try both the configurations and both works for me.
Appreciate your help!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!