04-01-2020 06:31 AM
Hello team,
We are sending all the traffic logs to our inhouse syslog servers. So whatever traffic is matching current security policies, all such traffic logs are forwarded to syslog server. Now in those logs, i am seeing everything like Source, Destination, port everything. Now our requirement, we need to send only specific logs to syslog for specific traffic. e.g. dont want to disclose source IP. How can i configure this?
Pls suggest.
04-01-2020 06:50 AM
I think you are looking for FILTER BUILDER under Log Forwarding Profiles. By default, it select 'All Logs' under Filter. But you can create custom filter as per your requirement. PFB snap for your ref. Once you create Filter, attach that Log Forwarding Profile to required security policies.
Hope it helps!
Mayur
04-01-2020 06:56 AM - edited 04-01-2020 07:00 AM
Hi @johnde ,
What @SutareMayur mentions will work and is very granular.
If you want to customize for your syslog-server you can also do this:
Goto your syslog server profile on the Device tab. There's a Custom Log Format tab ... click the Traffic one :
Add the field you want :
Hope this helps,
Kiwi.
04-01-2020 06:50 AM
I think you are looking for FILTER BUILDER under Log Forwarding Profiles. By default, it select 'All Logs' under Filter. But you can create custom filter as per your requirement. PFB snap for your ref. Once you create Filter, attach that Log Forwarding Profile to required security policies.
Hope it helps!
Mayur
04-01-2020 06:56 AM - edited 04-01-2020 07:00 AM
Hi @johnde ,
What @SutareMayur mentions will work and is very granular.
If you want to customize for your syslog-server you can also do this:
Goto your syslog server profile on the Device tab. There's a Custom Log Format tab ... click the Traffic one :
Add the field you want :
Hope this helps,
Kiwi.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!