WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 13: Reviewing and Working with Log Files2 Click Copy each file individually.3 Enter the file to copy in the Files to Copy box.4 Enter the destination for the file in the Copy to ThisDirectory box.5 Click Copy.The log file is copied to the new directory with the same filename.Forcing the rollover of log filesLog rollover refers to new log files being created while oldones are deleted or archived. In general, log files roll overbased on WSEP Status/Configuration settings. For moreinformation, see “Setting the interval for log rollover” onpage 212. However, you may occasionally want to force therollover of a log file.• From the WSEP Status/Configuration user interface,select File => Roll Current Log File.The old log file is saved as Firebox IP Time Stamp.wgl or FireboxName Time Stamp.wgl. The Event Processor continues writingnew records to Firebox IP.wgl or Firebox Name.wgl.Saving log files to a new locationAlthough log files are, by default, stored in a subdirectoryof the WatchGuard installation directory called /logs, youcan change this destination by using a text editor to edit thecontrold.wgc file.1 Open a text editor, such as Microsoft Wordpad.2 Use the text editor to open the controld.wgc file inthe WatchGuard installation directory.The default location is C:\ProgramFiles\WatchGuard\controld.wgc.3 Look for a line reading logdir: logs. Change logsto the complete or relative path name of the newdestination.For example, to change the destination to an archive directorywith the subdirectory WGLogs on the D: drive, the syntax islogdir: D:\Archive\WGLogs.4 Save your changes and exit the text editor.230 WatchGuard Firebox System

Working with Log Files5 Stop and restart the WatchGuard Security EventProcessor: Right-click the WatchGuard Security EventProcessor in the Windows desktop tray. Select StopService. Right-click the icon again and select StartService.New log files will be created in the specified directory. You canalso move any existing log files from the old location to the newone to avoid confusion.Setting log encryption keysThe log connection (but not the log file) between the Fireboxand an event processor is encrypted for security purposes.Both the management station and the WatchGuardSecurity Event Processor must have the same encryptionkey. From the WSEP Status/Configuration user interface:1 Select File => Set Log Encryption Key.The Set Log Encryption Key dialog box appears.2 Enter the log encryption key in the first box. Enter thesame key in the box beneath it to confirm.Sending logs to a log host at anotherlocationBecause they are encrypted by the Firebox, you can sendlog files over the Internet to a log host at another office.You can even send this traffic over the Internet from theFirebox at one office to the log host behind a second Fireboxat a remote office. One application of this feature mightinvolve configuring the Firebox at a remote office to storeits logs on a log host behind the Firebox at the main office.To do this, you must configure the Firebox at the remoteoffice such that it knows where and how to send the logfiles. The main office Firebox must be configured to allowthe log messages through the firewall to the log host.On the main office Firebox:1 Open Policy Manager with the current configurationfile.User Guide 231

Chapter 13: Reviewing and Working with Log Files2 Click Copy each file individually.3 Enter the file to copy in the Files to Copy box.4 Enter the destination for the file in the Copy to ThisDirectory box.5 Click Copy.The log file is copied to the new directory with the same filename.Forcing the rollover of log filesLog rollover refers to new log files being created while oldones are deleted or archived. In general, log files roll overbased on WSEP Status/Configuration settings. For moreinformation, see “Setting the interval for log rollover” onpage 212. However, you may occasionally want to force therollover of a log file.• From the WSEP Status/Configuration user interface,select File => Roll Current Log File.The old log file is saved as <strong>Firebox</strong> IP Time Stamp.wgl or <strong>Firebox</strong>Name Time Stamp.wgl. The Event Processor continues writingnew records to <strong>Firebox</strong> IP.wgl or <strong>Firebox</strong> Name.wgl.Saving log files to a new locationAlthough log files are, by default, stored in a subdirectoryof the <strong>WatchGuard</strong> installation directory called /logs, youcan change this destination by using a text editor to edit thecontrold.wgc file.1 Open a text editor, such as Microsoft Wordpad.2 Use the text editor to open the controld.wgc file inthe <strong>WatchGuard</strong> installation directory.The default location is C:\ProgramFiles\<strong>WatchGuard</strong>\controld.wgc.3 Look for a line reading logdir: logs. Change logsto the complete or relative path name of the newdestination.For example, to change the destination to an archive directorywith the subdirectory WGLogs on the D: drive, the syntax islogdir: D:\Archive\WGLogs.4 Save your changes and exit the text editor.230 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!