WatchGuard Technologies Firebox X manual Click File Merge log files

Page 50

Using LogViewer

Consolidating log files

You can put together two or more log files into one file. You can then use this file in Historical Reports, LogViewer, or some other tool to examine log data for an extended time interval. To merge more than one log file into one file:

The log files must be from the same Firebox

The log messages in the files must be in date and time order

The log files must be have been created with the same appliance software. You cannot merge a log file created with WFS appliance software with a log file created with Fireware appliance software, even if they are from the same Firebox.

Right-click the Log Server icon on your Windows toolbar and select Merge Log Files. Or, from the Log Server Status/Configuration interface:

1Click File > Merge log files.

The Merge Logfiles dialog box appears.

2Click Browse to find the files to put together.

3Click Merge.

The log files are put together and saved to a new file in the specified directory.

Updating .wgl log files to .xml format

When you migrate from an earlier version of WatchGuard System Manager to WSM 8.0 you can convert log files from .wgl to .xml format. This is also helpful if you manage a mixed network with different ver- sions of WSM. After converting, you can use your WSM 8.0 LogViewer or report tools on log files created with WatchGuard Management System 7.3 or earlier.

When you convert a log file from .wgl to .xml:

The XML file is usually smaller than the .wgl file. This is because XML log records are variable in length.

If you open the new XML file in an XML editor, you can see some duplicate entries. This is a function of the way Historical Reports made reports in WSM 7.3 and earlier. It does not cause problems in LogViewer or in Historical Reports for WSM 8.0.

44

WatchGuard System Manager

Image 50
Contents WatchGuardSystem Manager User Guide Address Contents Setting Up Logging and Notification Copy the online help system to more computersLogViewer Settings Importing Certificates Microsoft Internet Explorer 5.5Apache Software License, Version 2.0, January WatchGuard Management Server Getting StartedAbout WatchGuard System Manager Log ServerInstalling WatchGuard System Manager About Hardware and Appliance SoftwareLicense Keys Network addressesTrusted interface 1Network IP Addresses Without the FireboxExternal interface Optional interfacesUses 40-bit encryption Software encryption levelsBase StrongSetting Up Your Management Server Putting the Firebox into operation on your networkMaster password Admin passwordAfter Your Installation Installation TopicsWFS appliance software configuration modes Routed configurationDrop-in configuration Use the Quick Setup Wizard during installation Adding secondary networks to your configurationTo add a secondary networks, do one of these procedures Dynamic IP support on the external interfaceEntering IP addresses About slash notationInstalling the Firebox cables Installation Topics Threat responses, alerts, and expert advice Service and SupportLiveSecurity Service Solutions Easy software updatesLiveSecurity Service Broadcasts New from WatchGuard LiveSecurity Service Self Help ToolsBasic FAQs Interactive Support Forum Advanced FAQsKnown Issues Online TrainingWatchGuard Users Group Using the WatchGuard Users ForumWatchGuard Users Forum Online HelpCopy the online help system to more computers Product DocumentationTechnical Support Software requirementsType of Service Web Site Service TimeWe try to supply a solution in a maximum time of four hours HoursTraining and Certification About the WatchGuard System Manager Window Monitoring Your NetworkStarting WatchGuard System Manager From the Windows DesktopDevice Connecting to a FireboxDisconnecting from a Firebox LogDisconnecting from a Server Connecting to a ServerType the password for the Management Server Seeing Information about DevicesBranch Office VPN Tunnels Firebox StatusCertificates Pptp user VPN tunnels Seeing Information on Log ServersMobile user VPN tunnels No exclamation pointMonitoring VPNs Policy Manager About the WatchGuard ToolbarStarting Security Applications Firebox ManagerLog Viewer Quick Setup WizardHostWatch Historical ReportsLog Server collects logs from each WatchGuard Firebox Setting Up Logging and NotificationSetting Up the Log Server WatchGuard Log Server Configuration dialog box appears Configuration Guide for your version of appliance softwareSetting Global Logging and Notification Preferences Type the new log encryption key two times Click OKClick Save Changes or Close Click Save Changes Setting Global Logging and Notification Preferences Types of Log Messages Traffic Alarm Event DiagnosticReviewing and Working with Log Files Traffic log messagesLog File Names and Locations Alarm log messagesDiagnostic log messages Starting LogViewerBrowse to find the log file and click Open LogViewer Settings Changing LogViewer settings with WFS appliance software Click to set the format of the logs to the default colorsUsing LogViewer Select Edit FindPaste the data into any text editor Click File Merge log files Click Browse to find the files to put together Click MergeUsing LogViewer Using LogViewer Generating Reports of Network Activity Creating and Editing ReportsSelect the filter From Historical Reports, click AddType the report name Change the report definition Specifying a Report Time IntervalType the Firebox IP address or host name. Click Add Specifying Report Sections Type the number of items to put in the table Setting Report PropertiesTo consolidate report sections Exporting Reports Using Report Filters Complete the Filter tabsReport Sections and Consolidated Sections When finished, click OKRunning Reports Change the filter propertiesReport Sections and Consolidated Sections Session Summary Proxied Traffic Consolidated sections Report Sections and Consolidated Sections PKI in a WatchGuard VPN Managing Certificates Certificate AuthorityPublic Key Cryptography and Digital Certificates Certificate Authority CA Certificate Managing the Certificate AuthorityFrom the menu, select the correct GWvpn gateway name Management Server CA CertificateGenerate a New Certificate Find and Manage CertificatesPuts back a certificate that was revoked before RevokeReinstate DestroyManaging the Firebox X Edge Firebox Soho Importing CertificatesNetscape Communicator NetscapeManaging the Firebox X Edge or Soho Device Troubleshooting ideasAdministration System StatusFirewall Removing CertificatesSystem security and remote management LoggingSelect File Soho Management Clean up on PC Removing Certificates Appendix a Copyright and Licensing WatchGuard Firebox Software End-User License AgreementWatchGuard System Manager Copyright and Trademarks Licenses OpenSSL LicenseOriginal SSLeay License Apache Software License, Version 2.0, January Licenses Pcre License GNU Lesser General Public License Licenses Licenses Licenses GNU General Public License Licenses Licenses Licenses Sleepycat License Licenses Appendix B WatchGuard File Locations General File LocationsDefault File Locations Quick Setup WizardPolicy Manager for Fireware Appliance Software Firebox System Manager for Fireware Appliance SoftwareHostWatch for Fireware Appliance Software WatchGuard System Manager Policy Manager for WFS Appliance SoftwareFlash Disk Management for WFS Appliance Software Firebox System Manager for WFS Appliance SoftwareHostWatch for WFS Appliance Software LogViewerLog Server User Interface Management ServerWebBlocker Server Historical Reports Log Server for Fireware Appliance SoftwareLog Server for WFS Appliance Software Management Server User Interface Management Server Setup WizardLog Merge WatchGuard Certificate Authority Default File Locations Index Muvpn Wctp 100