03-Monitor

HomeSupportSecurityH3C SecPath F5000 FirewallConfigure & DeployConfiguration GuidesH3C Firewall Products Comware 7 Web Configuration Guide(E1196 E8371)-6W70003-Monitor
Table of Contents
Related Documents
02-Blacklist logs
Title Size Download
02-Blacklist logs 32.65 KB

Blacklist logs

 

This help contains the following topics:

·     Introduction

·     Restrictions and guidelines

·     Manage blacklist logs

¡     Import logs

¡     Export logs

Introduction

After you enable blacklist logging, the device outputs logs in the following situations:

·     A blacklist entry is manually added.

·     A blacklist entry is dynamically added by the scanning attack detection feature.

·     A blacklist entry is manually deleted.

·     A blacklist entry ages out.

A blacklist log records the following information:

·     Source IP address of the blacklist entry.

·     Remote IP address of the DS-Lite tunnel.

·     VPN instance (VRF) name.

·     Reason for adding or deleting the blacklist entry.

·     Aging time for the blacklist entry.

Restrictions and guidelines

·     Only one log operation (import, export, or delete) is allowed at a time.

·     Only one user can perform a log operation at a time. When you import, export, or delete logs, make sure no one else is performing a log operation.

Manage blacklist logs

Import logs

1.     Click the Monitor tab.

2.     In the navigation pane, select Security Logs > Blacklist Logs.

3.     Click Import.

4.     In the dialog box that opens, click Yes.

5.     Select a log file, and enter the password for the log file. The password was set when the file was exported.

Export logs

1.     Click the Monitor tab.

2.     In the navigation pane, select Security Logs > Blacklist Logs.

3.     Click Advanced search.

4.     On the page that opens, specify the search criteria to display the logs to be exported.

5.     Click Export.

6.     On the page that opens, configure the log export settings.

Table 1 Log export configuration items

Item

Description

Set password

Enter a password for encrypting the log files. This password is required when you view or import the exported log files.

Log range

Specify the range of logs to be exported. Options are:

·     All results—Exports all logs that satisfy the search criteria. The page displays the total number of logs to be exported.

·     Day on the current page—Exports logs of the day indicated by the Time field on the current page. You can define the ending page to decrease the number of logs to be exported.

 

7.     Select one of the following export methods.

¡     Export to one file—Exports logs to one file. When a small number of logs are to be exported, select this method.

¡     Export to files—Exports logs to multiple files. If more than 65000 logs are to be exported, select this method.

8.     Perform one of the following tasks as required:

¡     If you have selected Export to one file, click OK in the dialog box that opens.

¡     If you have selected Export to files, specify the number of logs to be exported to each file and click OK in the dialog box that opens.

When a log export to one file is complete, a dialog box opens, asking you whether to continue exporting the remaining logs to a new file.

-     To continue the export, click Yes.

-     To stop the export process, click No.

 

 

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网