Appendix C Log Formats and System Messages

Log Formats

In the LSM, you can view all the logs in the GUI. In addition, you can download a text-only version of the log and view it in a browser window or save it in a file. If you save a log in a file, you can then off load it to a remote syslog server. When downloading a log, the format is a steam of data separated by the delimiter specified in the GUI.

In the System Log, the fields displayed in the GUI are the same as the fields in the downloaded log. In the other five logs, the fields that are shown in the GUI are only a subset of what is available in the downloaded log file.

This section documents the fields that are in the downloaded versions of these logs. These field definitions are helpful when reading the downloaded log file. They contain the description of the data so that you can format the desired fields in a reporting program such as Excel or Access, or send it to a remote syslog server.

Delimiters

In the LSM GUI, on the Download Log page, you can specify one of the following delimiter formats:

tab (This is the default.) The field names do not appear on the tab delimited format.

comma (csv)

For both types of delimiters, the sub-fields within the Message field are always tab delimited. If a Message sub-field is not used a tab is inserted to move onto the next sub-field.

Alert and IPS Block Log Formats

An example of a comma-delimited IPS Block Log entry follows:

1, 2006-08-22

16:31:39,INFO,BLK,”Block v4 2 [3f937e55-31e9-11db-9452-

0800179bd3a4]

1 [00000001-0001-0001-0001-000000000164] icmp 0

192.168.1.1:0

209.191.93.52:0

1 0

0

[cc2f252a-1a57-4d00-8dc8-

a34e69992c46]

ANY [cc2f252a-1a57-4d00-8dc8-a34e69992c46] ANY

1156260699 0000000000 1

pt0

0

0 0 0324”

The following table describes the downloadable format of the Alert Log and IPS Block Log:

Table C–1: Alert and IPS Block Log Formats

Field Name

Sub-Field Name

Description

 

 

 

 

 

 

Seq

 

Unique sequence number for this log file.

 

 

 

Entry_time

 

Date and time of event. YYYY-MM-DD 24H:MI:SS

 

 

 

Sev

 

Severity of the alert, from least to most severe:

 

 

INFO = for information only

 

 

WARN = warning

 

 

ERR= error

 

 

CRIT = critical

 

 

 

292 X Family LSM User’s Guide V 2.5.1