Configuring Tracking Options in Security Policies

Configuring Tracking Options in Security Policies

Logs are useful if they show the traffic patterns you are interested in. Make sure your Security Policy tracks all necessary rules. When you track multiple rules, the log file is large and requires more disk space and management operations.

To balance these requirements, track rules that can help you improve your cyber security, help you understand user behavior, and are useful in reports.

To configure tracking in a rule:

  1. Right-click in the Track column.
  2. Select a tracking option.
  3. Install the policy.

Available Tracking Options

These are the available tracking options in the Track column:

Option Description
None Do not generate a log. This is the default setting in the Access Control policy.
Log This is the default option in the Threat Prevention policy. Show all the information that the Security Gateway used to match the connection. At a minimum, this includes the Source, Destination, Source Port, and Destination Port.
Custom Log - Track Settings

Log Generation Mode

Starting from R82.10, you can configure the log generation mode for the entire Access Control Rule Base.

Standard mode Sets the logging mode to per connection or per session, based on factors:

Logging Implied Rules

Starting from R82.10, you can configure the type of logs created for implied rules.

Note For versions earlier than R82.10, when selecting Log Implied Rules, the log generation mode is per connection.

Top Rules in the Logs View

In SmartConsole > Logs & Events > Logs view, R82.10 introduces Top Access Rules and Top Log Types statistics to help identify rules that generate excessive logging. For any high-logging rule, you can change the log generation mode to Per Session to significantly reduce log volume.