Configuring Tracking Options in Security Policies
Configuring Tracking Options in Security Policies
Logs are useful if they show the traffic patterns you are interested in. Make sure your Security Policy tracks all necessary rules. When you track multiple rules, the log file is large and requires more disk space and management operations.
To balance these requirements, track rules that can help you improve your cyber security, help you understand user behavior, and are useful in reports.
To configure tracking in a rule:
- Right-click in the Track column.
- Select a tracking option.
- Install the policy.
Available Tracking Options
These are the available tracking options in the Track column:
| Option | Description |
|---|---|
| None | Do not generate a log. This is the default setting in the Access Control policy. |
| Log | This is the default option in the Threat Prevention policy. Show all the information that the Security Gateway used to match the connection. At a minimum, this includes the Source, Destination, Source Port, and Destination Port. |
| Custom Log | - Track Settings |
- None
- Log
- Detailed Log - Similar to the Log option, but also logs the matched application, even if the rule does not specify an application.
- Extended Log - Similar to the Detailed option, but also shows a full list of URLs and files in the connection or the session. | | Alert | - None - Does not generate an alert.
- Alert - Generates a log of type Alert and runs a command.
- SNMP - Generates a log of type Alert and sends an SNMP alert.
- Mail - Generates a log of type Alert and sends an email to the administrator.
- User Defined Alert - Generates a log of type Alert and sends customized alerts. | | Accounting | Select this option to update the log at 10-minute intervals, showing how much data passed through the connection. |
Log Generation Mode
Starting from R82.10, you can configure the log generation mode for the entire Access Control Rule Base.
| Standard mode | Sets the logging mode to per connection or per session, based on factors: |
- The active Software Blades in the Layer
- Whether there are selected applications in the Services & Applications column
- Whether there are selected Data Types in the Content column. | | Aggregate mode | Generates logs per session and combines multiple connection logs into a single log. |
Logging Implied Rules
Starting from R82.10, you can configure the type of logs created for implied rules.
| Note | For versions earlier than R82.10, when selecting Log Implied Rules, the log generation mode is per connection. |
Top Rules in the Logs View
In SmartConsole > Logs & Events > Logs view, R82.10 introduces Top Access Rules and Top Log Types statistics to help identify rules that generate excessive logging. For any high-logging rule, you can change the log generation mode to Per Session to significantly reduce log volume.