765| External Ser vicesInterface DellPowerConnect W- Series ArubaOS 6.2 | User Guide
session-aclname
vlanvlan_id
For example:
ip access-listsessionfortinet
anyanysvc-httpredirectesi-groupfortinetdirectionbothblacklist
anyanyanypermit
user-roleguest
access-listsessionfortinet
Syslog Parser D omain and Rules
The followingsecti ons describehow to configure the syslog parserdomain and rules for the route-mode example
using the WebUI andC LI.

Add a New Syslog Parser Domain in the WebUI

To add a new syslog parser domain for the routed example:
1. Click A ddi n the SyslogParserDomains tab (Advanced Services > Exter nal Services > Syslog Parser Domain).
The system displays the new domain view.
2. I n the Domain Name text box, type the name of the domaint o be added.
3. I n the Server (IP Address) text box, type a valid IP address.
NOTE:You m ustensure that you type a valid IP address, because theIP address you type is not automatically validated against the
listof external servers that has been configured.
4. Click <<Add.
5. Click A pply.

Adding a New Parser Rule in the WebUI

To add a new syslog parser rule for the route-modeexample:
1. Click A ddi n the SyslogParserRulestab (Advanced Services > Exter nal Services > Syslog Parser Rule).
The system displays the new ruleview.
2. I n the Rule Namet ext box,ty pet hename of the rule to be added (in this example, “forti_virus”).
3. Click t he Enable checkboxto enable the rule.
4. I n the Condition Pattern text box, type the regularexpression to be used as the condition pattern. (In this
example,the expression “log_id=[0–9]{ 10}[]”searches for and matches a 10-digit string preceded by “log_id=”
and followedby one space.)
5. I n the drop-downMatc h list, use the drop-downmenu to select the match type (in this example, ipaddr).
6. I n the Match Pattern text box, type the regular expressionto be used as the match pattern (in this example,
“src=(.*)[]”).
7. I n the drop-downSet list, select t he set type (in this example, blacklist).
8. I n the drop-downPars er Group list, select one of the co nfiguredparser domain names (in this example, “forti_
domain”).
9. Click A pply.
In the CLI
Use these CLI commands to define a syslog parserdomain and the rule to be applied in the route-mode example
shown in Figure 347
esiparserdomainname