You can view logs through the log browsing view. You can view data from all types of Engines, and from third-party elements that are configured to send data to the SMCaaS Application.
You can browse, filter, and search for log data in the Logs view.
This guide provides the information you need to work with your Forcepoint product.
The SMC as a Service provides centralized access for configuring, managing, logging, and monitoring NGFWs that secure network connectivity and control business operations.
You can monitor Engines and view system summaries in the SMCaaS Application.
The Application Health Monitoring dashboard lets administrators monitor network and application layers connection quality.
The Logs view displays all logs for the SMCaaS Application.
The Fields pane provides several alternative views to the log entry that is selected.
Efficient use of the logs requires that you filter the records displayed in the Logs view.
You can filter logs based on the senders that created the entries.
You can specify which servers and storage folders to include.
You can use Log Data Contexts to select which type of log data is displayed in the Logs view.
You can add statistical items to a section of the Statistics view.
The Log Analysis view provides various tools to analyze logs, alerts, and audit entries.
By default, log entries are sorted according to their creation time. You can alternatively sort log entries according to any other column heading.
You can save snapshots of log, alert, and audit entries in the Log Analysis view.
The snapshots of log, alert, and audit entries are listed in the Monitoring view.
You can skip around logs from different time periods using the timeline.
The Logs view has two operating modes. One mode shows a fixed time frame, the other is a stream of current log entries, which also includes temporary entries.
To get more information about the source of traffic that triggered a log entry, you can look up the Whois record of IP addresses in log entries.
If you have saved copies of the most recent log and alert entries locally on the Engine, you can browse the log and alert entries on the command line of the Engine.
There are various ways in which you can customize how entries in the Log view are displayed.
You can export log entries in various ways and formats.
You can export lists of elements, logged data, diagrams and dashboards in PDF format.
You can use log entry details to generate new rules.
Elasticsearch is an open-source search Engine that runs on an external Elasticsearch server cluster. You can forward log data from Log Servers and Management Servers to an Elasticsearch cluster to improve the performance of browsing and searching for log entries, report generation, and other log-related features.
Reports are summaries of logs and statistics that allow you to combine large amounts of data into an easily viewable form.
Filters allow you to select data based on values that it contains. Most frequently, you use filters when viewing logs, but filters can also be used for other tasks, such as exporting logs and selecting data for reports.