03-Monitor

HomeSupportSecurityH3C SecPath F5000 FirewallConfigure & DeployConfiguration GuidesH3C Firewall Products Comware 7 Web Configuration Guide(E1196 E8371)-6W70003-Monitor
Table of Contents
Related Documents
10-Data filtering logs
Title Size Download
10-Data filtering logs 36.11 KB

Data filtering logs

 

This help contains the following topics:

·     Introduction

·     Restrictions and guidelines

·     Manage data filtering logs

¡     Import logs

¡     Export logs

¡     Aggregate logs

Introduction

The Data Filtering Log List page displays the logs generated by the data filtering module during file transmission, email sending and receiving, and website access. These logs help administrators customize data filtering profiles to reduce the risks of confidential information leakage and sensitive information leakage.

When configuring a data filtering profile, you can enable logging in data filtering rules. The data filtering module generates logs for data that match data filtering rules with the logging option enabled.

Restrictions and guidelines

·     Only one log operation (import, export, or delete) is allowed at a time.

·     Only one user can perform a log operation at a time. When you import, export, or delete logs, make sure no one else is performing a log operation.

Manage data filtering logs

Import logs

1.     Click the Monitor tab.

2.     In the navigation pane, select Security Logs > Data Filtering Logs.

3.     Click Import.

4.     In the dialog box that opens, click Yes.

5.     Select a log file, and enter the password for the log file. The password was set when the file was exported.

Export logs

1.     Click the Monitor tab.

2.     In the navigation pane, select Security Logs > Data Filtering Logs.

3.     Click Advanced search.

4.     On the page that opens, specify the search criteria to display the logs to be exported.

5.     Click Export.

6.     On the page that opens, configure the log export settings.

Table 1 Log export configuration items

Item

Description

Set password

Enter a password for encrypting the log files. This password is required when you view or import the exported log files.

Log range

Specify the range of logs to be exported. Options are:

·     All results—Exports all logs that satisfy the search criteria. The page displays the total number of logs to be exported.

·     Day on the current page—Exports logs of the day indicated by the Time field on the current page. You can define the ending page to decrease the number of logs to be exported.

 

7.     Select one of the following export methods.

¡     Export to one file—Exports logs to one file. When a small number of logs are to be exported, select this method.

¡     Export to files—Exports logs to multiple files. If more than 65000 logs are to be exported, select this method.

8.     Perform one of the following tasks as required:

¡     If you have selected Export to one file, click OK in the dialog box that opens.

¡     If you have selected Export to files, specify the number of logs to be exported to each file and click OK in the dialog box that opens.

When a log export to one file is complete, a dialog box opens, asking you whether to continue exporting the remaining logs to a new file.

-     To continue the export, click Yes.

-     To stop the export process, click No.

Aggregate logs

Perform this task to enable log aggregation. Log aggregation reduces the log volume and facilitates you to view the logs. With log aggregation enabled, the device aggregates service logs that meet the same aggregation criteria at the configured intervals. The log aggregation criteria include source IP address, destination IP address, application, source port, destination port, source security zone, destination security zone, file name, keyword group, keyword type, and match pattern.

Procedure

1.     Click the Monitor tab.

2.     In the navigation pane, select Security Logs > Data Filtering Logs.

3.     Click Log aggregation settings.

4.     On the page that opens, select the check box next to Enable and configure the aggregation interval.

5.     Click OK.

 

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网