Netgear STM300 STM 150-300-600 Reference Manual (PDF) - Page 194

Querying Logs, Email traffic, Web traffic, Virus, Spyware, Email filters, Content filters, System

Page 194 highlights

ProSecure Web/Email Security Threat Management (STM) Appliance Querying Logs The extensive log querying functions of the STM can help you to monitor the protection of the network and fine-tune the performance of the STM. For information about emailing logs and sending logs to a syslog server, see Configuring and Activating System, Email, and Syslog Logs on page 177. The STM generates logs that provide detailed information about malware threats and traffic activities on the network. You can search and view these logs through the Web Management Interface or save the log records in CSV or HTML format and download them to a computer (the downloading option is not available for all logs). You can also specify how many entries are displayed per page (the default setting is 15 entries). The STM provides nine types of logs: • Email traffic. All scanned incoming and outgoing email traffic. • Web traffic. All scanned incoming and outgoing Web traffic. • Virus. All intercepted viruses. • Spyware. All intercepted spyware. • Spam. All intercepted spam, including spam that was detected through the blacklist, real-time blacklist, and distributed spam analysis. • Email filters. All emails that are intercepted because of keyword, file type, file name, password, or size limit violations. • Content filters. All websites, URLs, and FTP sites that are intercepted because of Web category, blacklist, file type, or size limit violations. • System. The system event logs that include all system errors, informational messages, configuration changes, and system software updates. • Application. All intercepted application access violations. You can query and generate each type of log separately and filter the information based on a number of criteria. For example, you can filter the virus logs using the following criteria (other log types have similar filtering criteria): • Start date and time • End date and time • Protocols (HTTP, HTTPS, FTP, SMTP, POP3, and IMAP) • Virus name • Action (delete, quarantine, quarantine email, block email, and log) • Domain name • User name • Client IP address • Server IP address 194 | Chapter 6. Monitoring System Access and Performance

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261

194
|
Chapter 6.
Monitoring System Access and Performance
ProSecure Web/Email Security Threat Management (STM) Appliance
Querying Logs
The extensive log querying functions of the STM can help you to monitor the protection of the
network and fine-tune the performance of the STM.
For information about emailing logs and sending logs to a syslog server, see
Configuring and
Activating System, Email, and Syslog Logs
on page 177.
The STM generates logs that provide detailed information about malware threats and traffic
activities on the network. You can search and view these logs through the Web Management
Interface or save the log records in CSV or HTML format and download them to a computer
(the downloading option is not available for all logs). You can also specify how many entries
are displayed per page (the default setting is 15 entries).
The STM provides nine types of logs:
Email traffic
. All scanned incoming and outgoing email traffic.
Web traffic
. All scanned incoming and outgoing Web traffic.
Virus
. All intercepted viruses.
Spyware
. All intercepted spyware.
Spam
. All intercepted spam, including spam that was detected through the blacklist,
real-time blacklist, and distributed spam analysis.
Email filters
. All emails that are intercepted because of keyword, file type, file name,
password, or size limit violations.
Content filters
. All websites, URLs, and FTP sites that are intercepted because of Web
category, blacklist, file type, or size limit violations.
System
. The system event logs that include all system errors, informational messages,
configuration changes, and system software updates.
Application
. All intercepted application access violations.
You can query and generate each type of log separately and filter the information based on a
number of criteria. For example, you can filter the virus logs using the following criteria (other
log types have similar filtering criteria):
Start date and time
End date and time
Protocols (HTTP, HTTPS, FTP, SMTP, POP3, and IMAP)
Virus name
Action (delete, quarantine, quarantine email, block email, and log)
Domain name
User name
Client IP address
Server IP address