12.07.2015 Views

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

WSM Reference Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Event LogsGateway AntiVirus Service AlarmsDefaultNameAVMessage Format Example Message Caused Byalarm_name-”AV” alarm id,timestamp, message, source IP,destination IP, protocol, sourceport, destination port, sourceinterface, destination interface,virus name, sender, log_type=”al”alarm_name="AV"alarm_id="6001" time="Mon Aug 222:20:44 2004 (PST)" msg="SMTPFilename" src_ip="192.168.1.102"dst_ip="16.0.0.107" pr="tcp/smtp"src_port="1384" dst_port="25"src_intf="PPTP" dst_intf="1-Trusted" virus="Eicar-Test-Signature"sender="phillip@sjcqa.com"log_type="al"/These alarms are causedby events associated witheach AV rule of the SMTPproxy action.Intrusion Prevention Service AlarmsDefaultNameIPSMessage Format Example Message Caused Byalarm_name=”IPS”, alarm id,timestamp, message, source IP,destination IP, protocol, sourceport, destination port, sourceinterface, destination interface, IPSmessage, signature category,signature ID, log_type=”al”alarm_name="IPS"alarm_id="3001" time="Wed Aug 400:58:33 2004 (PST)" msg="IPS"src_ip="16.0.0.1"dst_ip="16.0.1.107" pr="tcp/http"src_port="4110" dst_port="80"src_intf="1-Trusted" dst_intf="0-External" ips_msg="WEB-ATTACKSkill command attempt"signature_cat="http-request"signature_id="1335"log_type="al"/These alarms are causedby different protocoltypes.Event LogsEvent logs are created because of Firebox user activity. Events that cause event logs include:• Firebox start up/shut down• Firebox and VPN authentication• Process start up/shut down• Problems with the Firebox hardware components• Any task done by the Firebox administratorOn a Firebox using Fireware appliance software, there are seven product components, including 27 differentlog modules, that create event and diagnostic log messages to send to the log server. The functionof each log module is shown in the table that follows.<strong>Reference</strong> <strong>Guide</strong> 41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!