‎09-16-2018 06:26 PM

Hi everyone,

To better understand  Security logs in streammode,  I set up the following  scenario:


Above we are using SRX  100.

Design goal:

 SRX  should send all SECURITY LOGS  in stream mode  to SYSLOG server

 SRX should send all other logs  to  SYSLOG server

Traffic , from destined to,  should be denied and logged, such logs  must be sent to  SYSLOG server  as it is a SECURITY LOG.


I noticed:

1)  Denied log  for  SRC  , DST,  is not being  sent to SYSLOG  server

2)  SRX instead still sends Security logs to  SYSLOG server


Please see the attached which shows SRX config,capture   taken on f0/1 on SRX for detail.


Let me know if I am missing anything.






I discovered   I have not configured   facility  severity level , Once i configured that,  I see  SRX  sends syslog in stream mode  to syslog


set security log stream TEST severity level debug.


I will leave this post  so it will come  handy  for others  if they encounter such issue.






‎09-16-2018 10:11 PM
Hi, First off have you got "set security log mode stream" In your configuration ? As Event and stream behave diferently (event mode which from memory is the default on Branch devices sends the loging information to the control plain while stream just sends it from the forwarding plane) Regards Shane
‎09-17-2018 12:34 AM



SRX can either send policy logs in "event" mode or either in "stream" mode, but it cannot be set up to use both at the same time.  Whenever you flip from event to stream, everything configured for policy logging under "system syslog" is ignored.


For SRX100 the default mode is "event".



Below is a KB article that explains the opposite behavior you are having right now. In that case, the policy logs matched using regex "RT_FLOW" only happens in the Routing Engine, but the configuration is being ignored if the device is set up in "stream".

