condition“log_id=[0-9]{10}[]”
match“src=(.*)[]”
setblacklist
enable

Showing ESI syslog parser rule informat ion:

showesiparserrules

Deleting a syslog parser rule:

noesiparserrulerule-name

Editing an existing sysl og parserrule

esiparserrulerule-name
conditionexpression
domainname
enable
match{ipaddrexpression|macexpression|userexpression}
no
positionposition
set{blacklist|rolerole}

Testing a parser rule

esiparserrulerule-name
test{filefilename|msgmessage}

Monitoring S yslog Parser Statistics

The followingsect ions describe how to monitor syslog parser stati stics using the WebUI and CLI.
In the WebUI
You can monitor syslog parser statistics i n the External Serversmonitoring page, accessed by selecting
Monitoring>Switch> ExternalServicesInterface>SyslogParserStatistics.
The SyslogParserStatistics view di splays statistics such as the number of matches and number of users per rule,as
wellas t henumber of respective actions fired by the syslog parser.
NOTE:The SyslogParserStatisticsview al sodi splaysthe last refresh time stamp and includes a RefreshNowbutton, to allow the
statisticsinformation to be refreshed manually. There is no automatic refresh on this page.
In the CLI
showesiparserstats
Sample Route-m ode ESI Topology
This section introduces the configuration for a sampleroute-mode topology using the controller and Fortinet Anti-
Virus gateways. In route mode, thet rustedand untrusted interfaces between the controllerand the Fortinet gateways
are on differentsubnets. The following figure shows an exampleroute-mode topology.
NOTE:ESI wi thFortinet Anti-Virus gateways is supported only in route mode.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide ExternalServicesInter face |760