- Table of Contents
-
- 07-System
- 01-Track
- 02-BFD
- 03-NQA
- 04-Basic log settings
- 05-Email server
- 06-Session log settings
- 07-Sandbox log settings
- 08-Threat log settings
- 09-Application audit log settings
- 10-NetShare log settings
- 11-URL filtering log settings
- 12-Attack defense log settings
- 13-Reputation log settings
- 14-Bandwidth alarm logs
- 15-Configuration log settings
- 16-Security policy log
- 17-Terminal identification logging
- 18-Heartbeat log settings
- 19-WAF log settings
- 20-Bandwidth management logs
- 21-Report settings
- 22-Session settings
- 23-Signature upgrade
- 24-Software upgrade
- 25-License management
- 26-Administrators
- 27-Date and time
- 28-SNMP
- 29-Configuration management
- 30-Reboot
- 31-About
- 32-Ping
- 33-Tracert
- 34-Packet capture
- 35-Webpage Diagnosis
- 36-Diagnostic Info
- 37-Packet trace
- 38-Fast Internet Access
- Related Documents
-
Title | Size | Download |
---|---|---|
06-Session log settings | 23.77 KB |
Session log settings
Introduction
Session logs provide information about user access, IP address translation, and network traffic for security auditing. They can be output in flow log or fast log output format.
The device supports time-based or traffic-based logging:
· Time-based logging—The device outputs session logs regularly.
· Traffic-based logging—The device outputs a session log when the traffic amount of a session reaches a threshold.
If you set both time-based and traffic-based logging, the device outputs a session log when whichever is reached. After outputting a session log, the device resets the traffic counter and restarts the interval for the session.
Session logs can be generated only when session logging is enabled on interfaces.
Configure session log settings
Procedure
1. Click the System tab.
2. Select Log Settings > Session Log Settings.
3. Configure session logging.
Table 1 Session logging configuration items
Item |
Description |
Log type |
Select a log type. By default, flow log is used. |
Session creation logging |
This feature enables the device to output a session log when a session entry is created. |
Session deletion logging |
This feature enables the device to output a session log when a session entry is removed. |
Traffic-based logging |
Set either the byte-based threshold or the packet-based threshold. The device outputs a session log when the traffic amount of a session reaches the set threshold. |
Time-based logging |
Set the time-based threshold for the device to output session logs. |
4. Click Apply.
5. Click Add interface to enable session logging on the specified interface.
Table 2 Configuration items for enabling session logging on an interface
Item |
Description |
IP version |
Select an IP version, IPv4 or IPv6. |
Port |
Select a port. You can also enable session logging on the specified directions of the port. |
ACL |
Select an ACL to filter IPv4 or IPv6 sessions that can trigger session logging on the interface. If no ACL is specified, the device outputs session logs for all IPv4 or IPv6 sessions on the interface. |
6. Click OK.
7. Verify the configuration on the Session Logging page.