Configure protocols for advanced logging

Configure application protocol logging to enable the system to capture and log connection data for specific protocols, providing detailed visibility into network traffic for security monitoring, compliance, and troubleshooting purposes.

Advanced logging for application protocols allows you to monitor and analyze network connections by capturing detailed information about specific application protocols. This feature is configured at the access control policy level and can be applied to individual rules within the policy.

Before you begin

Ensure that you have enabled the advanced logging feature for the access control policy that you want to modify.

Follow these steps to configure protocols for advanced logging:

Procedure


Step 1

Choose Policies > Security policies > Access Control.

Step 2

Click Edit (edit icon) next to the access control policy you want to edit.

If View (View button) appears instead, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Step 3

In the access control policy editor, you have the options to add a new rule or edit an existing rule.

  • To add a new rule, click Add Rule.

  • To edit an existing rule, click Edit (edit icon).

Step 4

Click Advanced Logging.

Step 5

Check the check box next to the application protocol for which you want to log the connection.

Caution

Enabling logging for all the protocols in a Firewall Threat Defense device might affect its performance, because the device must extract data, convert it to targeted formatting, and send it to the configured destination.

Step 6

Click Confirm.

Step 7

Click Apply to save the rule.

Step 8

Click Save to save the policy.


The selected application protocols are now configured for advanced logging in the access control policy. Connection data for these protocols will be captured and logged according to the policy configuration.

What to do next

Deploy configuration changes.