13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Working with log filesIP header lengthLength, in octets, of the IP header for this packet. A header length that is not equalto 20 indicates that IP options were present. Default = HideTTL (time to live)The value of the TTL field in the logged packet. Default = HideSource addressThe source IP address of the logged packet. Default = ShowDestination addressThe destination IP address of the logged packet. Default = ShowSource portThe source port of the logged packet. UDP or TCP only. Default = ShowDestination portThe destination port of the logged packet. UDP or TCP only. Default = ShowDetailsAdditional information appears after the previously described fields, includingdata about IP fragmentation, TCP flag bits, IP options, and source file and linenumber when in trace mode. If <strong>WatchGuard</strong> logging is in debug or verbose mode,additional information is reported. In addition, the type of connection may bedisplayed in parentheses. Default = ShowWorking with log filesThe <strong>Firebox</strong> is continually writing messages to log files on the LiveSecurity EventProcessor. Because current log files are always open, they cannot be copied, moved,or merged using traditional copy tools; you should use LiveSecurity Event Processorutilities to work with active log files.Unlike with other <strong>Firebox</strong> <strong>System</strong> utilities, you cannot access the LiveSecurity EventProcessor user interface from Control Center. To open the Event Processor userinterface:• Right-click the Event Processor icon in the Windows system tray and select OpenLog Center.Consolidating logs from multiple locationsYou can merge two or more log files into a single file. This merged file can then beused with Historical Reports, LogViewer, HostWatch, or some other utility toexamine log data covering an extended period of time. From the LiveSecurity EventProcessor:1 Select File => Copy or Merge Log Files.2 Click Merge all files to one file. Enter the name of the merged file.3 Enter the files to merge in the Files to Copy box.4 Enter the destination for the files in the Copy to This Directory box.106

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!