12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Types of Log MessagesTypes of Log MessagesThe Firebox® sends four types of log messages. The type appears in the text of the message. The fourtypes of log messages are:• Traffic• Alarm• Event• DiagnosticTraffic log messagesThe Firebox sends traffic log messages as it applies packet filter and proxy rules to traffic that goesthrough the Firebox.Alarm log messagesAlarm log messages are sent when an event occurs that triggers the Firebox to do a command. Whenthe alarm condition is matched, the Firebox sends an Alarm log message to the Traffic Monitor and LogServer and then it does the specified action.You can set some alarm log messages. For example, you can use Policy Manager to configure an alarmto occur when a specified value matches or is more than a threshold. Other alarm log messages are setby the appliance software, and you cannot change the value. For example, the Firebox sends an alarmlog message when a network connection on one of the Firebox interfaces fails or when a Denial of Serviceattack occurs. For more information about alarm log messages, see the Reference <strong>Guide</strong>.There are eight categories of alarm log messages: System, IPS, AV, Policy, Proxy, Counter, Denial of Service,and Traffic. The Firebox does not send more than 10 alarms in 15 minutes for the same conditions.Event log messagesThe Firebox sends an event log messages because of user activity. Actions that can cause the Firebox tosend an event log message include:• Firebox start up and shut down• Firebox and VPN authentication• Process start up and shut down• Problems with the Firebox hardware components• Any task done by the Firebox administratorDiagnostic log messagesDiagnostic log messages include information that you can use to help troubleshoot problems. There are27 different product components that can send diagnostic log messages. You can select whether thediagnotic log messages appear in Traffic Monitor, as described in “Enabling advanced diagnostics” onpage 85.Log File Names and LocationsThe Firebox® sends log messages to a primary or backup Log Server. The default location for the log fileis My Documents > My <strong>WatchGuard</strong> > Shared <strong>WatchGuard</strong> > logs.The name of the log file shows:90 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!