Security

last person joined: yesterday 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  SSG520 log persistence

    Posted 10-26-2015 10:15

    Hello,

     

    I've inherited a SSG520 firewall and I'm attempting to get a better handle on the logs. I need to track what certain policies are blocking (or not), and unfortunately the built-in logs fill up and clear out too fast for my use. Is there a way I can set logs to export to an external location, or some other trick to make them persist longer?

     

    There's a netscreen 25 I'd like to do something similar with, as well. 

     

    Thanks for your time.



  • 2.  RE: SSG520 log persistence

    Posted 10-26-2015 16:53

    ScreenOS logs auto-roll simply based on storage space available.  So the options are:

     

    • Log less things and thus have more room for the rest
    • Add a USB storage and point logs here to increase space
    • Send logs to a syslog server for central storage


  • 3.  RE: SSG520 log persistence

    Posted 11-02-2015 06:28

    Thanks for the info, spuluka. 

     

    Would you point me towards instructions for sending logs to a syslog server? I'm still learning my way around this interface. 



  • 4.  RE: SSG520 log persistence
    Best Answer

    Posted 11-03-2015 05:04

    These are the basic syslog setup instructions.

     

    https://kb.juniper.net/InfoCenter/index?page=content&id=KB4759



  • 5.  RE: SSG520 log persistence

    Posted 11-03-2015 12:35

    That should do it, thanks again.



  • 6.  RE: SSG520 log persistence

    Posted 11-04-2015 11:23

    Is there a unique format to the logs from Juniper? I'm sending these logs over to a "loganalyzer" log server but the formatting seems off. Each "log" on the log server seems to contain a mishmash of multiple logs from the firewall. 



  • 7.  RE: SSG520 log persistence

    Posted 11-07-2015 05:45

    I've not seen a combination type behavior before.  But I suspect this is a configuration issue on the syslog software.  Each event is sent as a separate line with the fields separated.  The syslog server should seem them as separate events.

     

    I suspect it may be bundling multiple events together, probably based on the event time or received time parameter in an effort to be helpful.  These are generally referred to in syslog servers as "parsers" or "event correlation" so I would check those terms in the help search for the software.

     

    the events you receive and save are the same you would see in the reports menu and traffic logs on the device itself.