Logging settings for access control policies
Logging settings for access control policies are configuration option that allow you to configure default syslog destinations for the current access control policy. The settings are applicable to the access control policy and all the included decryption, prefilter, and intrusion policies unless the syslog destination settings are explicitly overridden with custom settings in included rules and policies.
To configure logging settings for an access control policy, select Logging from the More drop-down arrow at the end of the packet flow line.
You can configure default syslog destinations and syslog ALERT for the access control policy. The settings are applicable to the access control policy and all the included decryption, prefilter, and intrusion policies unless the syslog destination settings are explicitly overridden with custom settings in included rules and policies.
Logging for connections handled by the default action is initially disabled.
Intrusion settings and file and malware settings are effective only after you have selected an option at the top of the page for sending syslog messages generally.
Default syslog settings
Default syslog settings provide two destination options:
-
: Events are sent based on the selected syslog ALERT as configured using the instructions in Create a syslog alert response. You can select the syslog ALERT from the list or add one by specifying the name, logging host, port, facility, and severity.
When using this option, the system sends syslog messages to the server using the Management interface. Ensure there is a route from the Management interface to the syslog server, or messages will not arrive at the server.
-
: Connection or intrusion events are sent with the selected severity to syslog collectors configured in Platform Settings. Using this option, you can unify the syslog configuration by configuring it in platform settings and reusing the settings in access control policy. Severity selected in this section is applied to all connection and intrusion events. The default severity is ALERT.
Intrusion settings
Intrusion settings include these options:
-
Send syslog messages for intrusion events: Send intrusion events as syslog messages. The defaults set above are used unless you override them.
-
Show overrides or Hide overrides: If you want to use the default syslog destination and severity, leave these options empty. Otherwise, you can set a different syslog server destination for intrusion events, and change the severity of the events.
File and malware settings
File and malware settings include these options:
-
Send syslog messages for file and malware events: Send file and malware events as syslog messages. The defaults set above are used unless you override them.
-
Show overrides or Hide overrides: If you want to use the default syslog destination and severity, leave these options empty. Otherwise, you can set a different syslog server destination for file and malware events, and change the severity of the events.