Define logging options for Inspection rules
Inspection rules can create a log or alert entry each time they match.
By default, an Inspection Policy uses the logging options set in a previous Exception rule with Continue as its action. If no such rule exists, Engines, Virtual Engines, Layer 2 Engines, and Virtual Layer 2 Engines log connections by default. IPS engines and Virtual IPS engines do not log connections by default.
Each individual Inspection rule can be set to override the default values of the engine role.
For more details about the product and how to configure features, click Help or press F1.
Steps
Logging - Select Logging Options dialog box (Inspection rules)
Use this dialog box to define logging options for global Inspection rules.
Option | Definition |
---|---|
Override Default Settings | When selected, overrides default settings. |
Option | Definition |
---|---|
Log Level | Select one of these options:
|
Alert | When the Log Level is set to Alert, specifies the Alert that is sent. |
Recording | |
Store Excerpt | Stores an excerpt of the packet that matched. The maximum recorded excerpt size is 4 KB. This option allows you to quickly view the payload in the Logs view. |
Record Traffic | Records the traffic up to the limit you set in the Recording Length field. This option allows storing more data than the Excerpt option. |
Recording Length | Sets the length of the recording for the Record option in bytes. |