McAfee MAP-3300-SWG Product Guide - Page 269

System Log Settings, Table 268, Option definitions

Page 269 highlights

Overview of System features Logging, Alerting and SNMP Access control list Table 268 Option definitions Option Definition Access control list The appliance is set to allow SNMP queries from all devices. We recommend that you change the settings to allow access from known devices only. Specify the IP address numbers of the devices that can read the appliance's MIB parameters. System Log Settings Use this page to specify standard or extended system logging and the events to be recorded in the system log. You can also send logs to off-box servers. System | Logging, Alerting and SNMP | System Log Settings Syslog is a method for delivering log information across a network, usually via UDP port 514. The syslog protocol and message format are defined in RFC 3164. Extended logging creates a structured output log file using the syslog protocol. The extended logging option provides name-value pairs for each logged event. Table 269 Option definitions Option Enable system log events Definition Enables system logging (syslog) information to be collected and delivered to the on-appliance logging system, or sent to an off-box solution. Select the type of logging format that you want to use. This option creates an output log file that is structured so that it can be easily read by third-party applications and used to generate custom reports. Due to the amount of data generated, we recommend that this option is only enabled when using TCP syslog. Choose from: • Original • Splunk • Arcsight Log events to the syslog for the following event types: Conversation events and Aggregated data events are not reported in the extended logging format. Click View the system logs to see the log files on the appliance. Specify the events to capture within the syslog. To prevent very large log files, we recommend that you record only events that you want to monitor closely, and deselect the events when you have finished. The appliance cannot store the transport events produced by heavy traffic for long periods. We recommend that you use the off-box syslog option to forward the transport events to a central syslog server. McAfee Email and Web Security Appliances 5.6.0 Product Guide 269

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Access control list
Table 268
Option definitions
Option
Definition
Access control list
The appliance is set to allow SNMP queries from all devices. We recommend that you
change the settings to allow access from known devices only. Specify the IP address
numbers of the devices that can read the appliance’s MIB parameters.
System Log Settings
Use this page to specify standard or extended system logging and the events to be recorded in the
system log. You can also send logs to off-box servers.
System
|
Logging, Alerting and SNMP
|
System Log Settings
Syslog is a method for delivering log information across a network, usually via UDP port 514. The
syslog protocol and message format are defined in RFC 3164.
Extended logging creates a structured output log file using the syslog protocol. The extended logging
option provides name–value pairs for each logged event.
Table 269
Option definitions
Option
Definition
Enable system
log events
Enables system logging (syslog) information to be collected and delivered to the
on-appliance logging system, or sent to an off-box solution.
Select the type of logging format that you want to use. This option creates an output
log file that is structured so that it can be easily read by third-party applications and
used to generate custom reports. Due to the amount of data generated, we
recommend that this option is only enabled when using TCP syslog. Choose from:
• Original
• Splunk
• Arcsight
Conversation events and Aggregated data events are not reported in the extended
logging format.
Click
View the system logs
to see the log files on the appliance.
Log events to
the syslog for
the following
event types:
Specify the events to capture within the syslog. To prevent very large log files, we
recommend that you record only events that you want to monitor closely, and deselect
the events when you have finished.
The appliance cannot store the transport events produced by heavy traffic for long
periods. We recommend that you use the off-box syslog option to forward the
transport events to a central syslog server.
Overview of System features
Logging, Alerting and SNMP
McAfee Email and Web Security Appliances 5.6.0 Product Guide
269