Define logging options for Inspection rules
Inspection rules can create a log or alert entry each time they match.
By default, an Inspection Policy uses the logging options set in a previous Exception rule with Continue as its action. If no such rule exists, Firewalls, Virtual Firewalls, Layer 2 Firewalls, and Virtual Layer 2 Firewalls log connections by default. IPS engines and Virtual IPS engines do not log connections by default.
Each individual Inspection rule can be set to override the default values of the engine role.
For more details about the product and how to configure features, click Help or press F1.
Steps
Logging - Select Logging Options dialog box (Inspection rules)
Use this dialog box to define logging options for global Inspection rules.
Option | Definition |
---|---|
Override Settings Inherited from Continue Rule(s) | When selected, overrides settings defined in Continue rules higher up in the policy. |
Log Level | Select one of these options:
|
Alert | When the Log Level is set to Alert, specifies the Alert that is sent. |
Recording | |
Excerpt | Stores an excerpt of the packet that matched. The maximum recorded excerpt size is 4 KB. This option allows you to quickly view the payload in the Logs view. |
Store Additional Protocol Details | When selected, traffic is sent to be inspected. Some additional log data might be generated. |
Record | Records the traffic up to the limit you set in the Record Length field. This option allows storing more data than the Excerpt option. |
Record Length | Sets the length of the recording for the Record option in bytes. |