HP 6125XLG R2306-HP 6125XLG Blade Switch Network Management and Monitoring Con - Page 65

Managing security logs

Page 65 highlights

Step 4. Enable log file overwrite-protection 5. (Optional.) Specify the maximum size of the log file. 6. (Optional.) Specify the directory to save the log file. Command Remarks info-center logfile overwrite-protection [ all-port-powerdown ] By default, log file overwrite-protection is disabled. With the all-port-powerdown keyword specified in the command, the device shuts down all the physical ports except for the console port, the management Ethernet port, and IRF ports when the log file is full or the free space of the flash is not enough. To restore normal state, backup the log file, delete the original log file to release storage space, and then bring up the ports. This feature is available only in FIPS mode. For more information about FIPS, see Security Configuration Guide. info-center logfile size-quota size The default setting is 10 MB. To ensure normal operation, set the size argument to a value between 1 MB and 10 MB. info-center logfile switch-directory dir-name By default, the log file is saved in the directory flash:/logfile. The configuration made by this command cannot survive an IRF reboot or a master/subordinate switchover. 7. Save the logs in the log file buffer to the log file. • Method 1: Configure the interval to perform the save operation: Use either method. info-center logfile frequency freq-sec By default, the system saves logs to the log file every 86400 seconds. • Method 2: Manually save the The logfile save command is logs in the log file buffer to the available in any view. log file: logfile save Managing security logs Security logs are very important for locating and troubleshooting network problems. Generally, security logs are output together with other logs. It is difficult to identify security logs among all logs. To solve this problem, you can save security logs into the security log file without affecting the current log output rules. 59

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148

59
Step
Command
Remarks
4.
Enable log file
overwrite-protection
info-center logfile
overwrite-protection
[
all-port-powerdown
]
By default, log file
overwrite-protection is disabled.
With the
all-port-powerdown
keyword specified in the
command, the device shuts down
all the physical ports except for the
console port, the management
Ethernet port, and IRF ports when
the log file is full or the free space
of the flash is not enough. To
restore normal state, backup the
log file, delete the original log file
to release storage space, and then
bring up the ports.
This feature is available only in
FIPS mode. For more information
about FIPS, see
Security
Configuration Guide
.
5.
(Optional.) Specify the
maximum size of the log file.
info-center logfile size-quota
size
The default setting is 10 MB.
To ensure normal operation, set the
size
argument to a value between
1 MB and 10 MB.
6.
(Optional.) Specify the
directory to save the log file.
info-center logfile switch-directory
dir-name
By default, the log file is saved in
the directory flash:/logfile.
The configuration made by this
command cannot survive an IRF
reboot or a master/subordinate
switchover.
7.
Save the logs in the log file
buffer to the log file.
Method 1: Configure the
interval to perform the save
operation:
info-center logfile frequency
freq-sec
Method 2: Manually save the
logs in the log file buffer to the
log file:
logfile save
Use either method.
By default, the system saves logs to
the log file every 86400 seconds.
The
logfile save
command is
available in any view.
Managing security logs
Security logs are very important for locating and troubleshooting network problems. Generally, security
logs are output together with other logs. It is difficult to identify security logs among all logs.
To solve this problem, you can save security logs into the security log file without affecting the current log
output rules.