12.07.2015 Views

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Alarm LogsHTTP Proxy Traffic Log MessagesText in Message FieldAssociated FieldsHTTP REQopdstnameargHTTP HEADER IPS MATCHips_msgsignature_idHTTP BODY IPS MATCHips_msgsignature_idHTTP BYTECOUNT UPDATEMessage MeaningValue that appears in associated field(s)Auditing information about an HTTP request.HTTP request methodhostname from requested URLpath and query-string from requested URLThe HTTP header matches an IPS signagure.description of the signature that matchedthe signature ID of the rule that matchedThe HTTP body matches an IPS signature.description of the signature that matchedthe signature ID of the rule that matchedAuditing information for an HTTP request that has a very largeresponse.TCP Proxy Traffic Log MessagesText in Message FieldAssociated FieldsMessage MeaningValue that appears in associated field(s)TCP REQoutgoing_msg the mode the handler is in.TCP IPS MATCHips_msgsignature_idTCP proxy found an IPS signature match.description of the signature that matchedthe signature ID of the rule that matchedAlarm LogsAlarm logs are sent when an alarm condition is met. The Firebox sends the alarm log to the Traffic Monitorand Log Server and triggers the specified action.Some alarms are set in your Firebox configuration. For example, you can use Policy Manager to configurean alarm to occur when a certain threshold is met. Other alarms are set by default. The Firebox sendsan alarm log when a network connection on one of the Firebox interfaces fails. This cannot be changedin your configuration. The Firebox never sends more than 10 alarms in 15 minutes for the same set ofconditions.There are eight categories of alarm logs: System, IPS, AV, Policy, Proxy, Probe, Denial of service, and Traffic.There is a table below for each category of alarms, showing the format of the alarm log messages ineach category.36 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!