Define logging options for Exception rules

Inspection Exception rules can create a log or alert entry each time they match.

Firewalls, Virtual Firewalls, Layer 2 Firewalls, and Virtual Layer 2 Firewalls log connections by default. You can override the default logging options in an Exception rule with Continue as its action. IPS engines and Virtual IPS engines do not log connections by default.

Each individual Exception rule can be set to override the default values of the engine role.

  For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Switch to the Exceptions tab.
  2. Double-click the Logging cell of an Exception rule.
  3. Set the options, then click OK.
    Note: Storing or viewing the packets’ payload can be illegal in some jurisdictions due to laws related to the privacy of communications.

Logging - Select Rule Options dialog box (Inspection Exceptions)

Use this dialog box to define Exception rule logging options in Inspection Policies.

Option Definition
Override Settings Inherited from Continue Rule(s) When selected, overrides settings defined in Continue rules higher up in the policy.
Log Level Select one of these options:
  • None — Does not create any log entry.
  • Transient — Creates a log entry that is displayed in the Current Events mode in the Logs view, but is not stored.
  • Stored — Creates a log entry that is stored on the Log Server.
  • Essential — Creates a log entry that is shown in the Logs view and saved for further use.
  • Alert — Triggers the alert you select.
Alert When the Log Level is set to Alert, specifies the Alert that is sent.
Override Settings Inherited from Continue Rule(s) When selected, overrides settings defined in Continue rules higher up in the policy.
Excerpt Stores an excerpt of the packet that matched. The maximum recorded excerpt size is 4 KB. This option allows you to quickly view the payload in the Logs view.
Store Additional Protocol Details When selected, traffic is sent to be inspected. Some additional log data might be generated.
Record Records the traffic up to the limit you set in the Record Length field. This option allows storing more data than the Excerpt option.
Record Length Sets the length of the recording for the Record option in bytes.