SonicOS 8 Monitor

Table of Contents

Display Options

Customize the Events log to display as many or few columns that meet your needs.

To select which columns to display:

  1. Navigate to MONITOR | Logs > System Logs.
  2. Click Grid Settings icon . The Grid Settings dialog displays:

  3. Select the items you want to appear as columns in the System Log.

    General General information about the log event.
    Time

    Local date and time the event occurred.

    This option is selected by default. It is dimmed, and cannot be deselected.

    ID

    Identifying number for the event.

    This option is selected by default. It is dimmed, and cannot be deselected.

    CategoryCategory of the event. This option is selected by default.
    GroupGroup designation of the event.
    EventName of the event.
    Msg TypeType of message; usually Standard Message String.
    Priority

    Priority level of the event, such as Inform (information) or Error.

    This option is selected by default.

    MessageInformation about the event.

    Interface

    Information about the protocol of the packet triggering the event.
    Source

    Name of the source device, if applicable. This option is selected by default.

    Source IP

    IP address of the source device.

    Source Port

    Port number of the source.

    Source Interface

    Source network and IP address, if applicable.

    Destination

    Name of the destination device, if applicable. This option is selected by default.

    Destination IP

    IP address of the destination device.

    Destination Port

    Port number of the destination.

    Destination Interface

    Destination network and IP address, if applicable.

    Protocol Information about the NAT policy in effect, if any.
    Source NameProtocol source name.
    Source NAT IPSource address from the Source NAT IP address pool.
    Source NAT PortPort number for the Source NAT.
    In SPIIndicates whether the ingress packet is in Stateful Packet Inspection (SPI) mode, if applicable.
    Destination NameProtocol destination name.
    Destination NAT IPDestination address from the Source NAT IP address pool.
    Destination NAT PortPort number for the Destination NAT.
    Out SPIIndicates whether the egress packet is in Stateful Packet Inspection (SPI) mode, if applicable.
    IP ProtocolProtocol used to send error and control messages, if known. This option is selected by default.
    ICMP TypeICMP packet’s ICMP type, if known.
    ICMP CodeICMP packet’s ICMP code, if known.
    Connection Information about SPI, Access and IDP Rules, and policies, if any.
    TX BytesNumber of bytes transmitted.
    RX BytesNumber of bytes received.
    Access RuleName of the Access Rule triggering the event, if any.
    NAT PolicyName of the NAT policy.
    VPN PolicyName of the VPN policy triggering the event, if any.
    User NameName of the user whose action triggered the event.
    Session TimeDuration of the session before the event.
    Session TypeType of session triggering the event.
    IDP RuleName of the IDP Rule triggering the event, if any.
    IDP PriorityPriority of the IDP Rule.
    Application Information about the application being used.
    HTTP OPNPCS object op requestMethod HTTP OP code.
    URLURL of the NPCS object op requestMethod HTTP OP code.
    HTTP ResultHTTP result code (such as, 200, 403) of Website hit rpkt cn1Label Packet received.
    Block CategoryBlock category that triggered the event.
    ApplicationThe application being used.
    Others Information about the user, session, and application, if known.
    FW ActionConfigured firewall action. If no action has been specified, displays N/A.
    Notes

    Includes notes. This option is selected by default.

  4. When done, click Apply to preserve any changes or click Restore Default to revert back to the default settings.

You can perform the following actions on the System Logs page:

  • To export the logs in CSV, TXT files, and email, click Export icon and select the required format
  • To clear the logs from the table, click Clear Logs icon
  • To refresh the page, click Refresh icon
  • To view more details of the log, click the triangle icon of the log