Cisco Cisco Web Security Appliance S390 Betriebsanweisung

Seite von 430
 
20-6
Cisco AsyncOS 8.0.6 for Web User Guide
 
Chapter 20      Monitor System Activity Through Logs
  Adding and Editing Log Subscriptions
Log Fields
(W3C Access Logs)
Allows you to choose the fields you want to include in the W3C access log.
Select a field in the Available Fields list, or type a field in the Custom Field 
box, and click Add. 
The order the fields appear in the Selected Log Fields list determines the 
order of fields in the W3C access log file. You can change the order of fields 
using the Move Up and Move Down buttons. You can remove a field by 
selecting it in the Selected Log Fields list and clicking Remove.
You can enter multiple user defined fields in the Custom Fields box and add 
them simultaneously as long as each entry is separated by a new line (click 
Enter) before clicking Add.
When you change the log fields included in a W3C log subscription, the log 
subscription automatically rolls over. This allows the latest version of the log 
file to include the correct new field headers. 
Log Compression
Specifies whether or not rolled over files are compressed. AsyncOS 
compresses log files using the gzip compression format.
Log Exclusions 
(Optional)
(Access Logs)
Allows you to specify HTTP status codes (4xx or 5xx only) to exclude the 
associated transactions from an access log or a W3C access log. 
For example, entering 401 will filter out authentication failure requests that 
have that transaction number.
Log Level
Specifies the level of detail for log entries. Choose from:
Critical. Includes errors only. This is the least detailed setting and is 
equivalent to the syslog level “Alert.”
Warning. Includes errors and warnings. This log level is equivalent to 
the syslog level “Warning.”
Information. Includes errors, warnings and additional system 
operations. This is the default detail level and is equivalent to the syslog 
level “Info.”
Debug. Includes data useful for debugging system problems. Use the 
Debug log level when you are trying to discover the cause of an error. 
Use this setting temporarily, and then return to the default level. This log 
level is equivalent to the syslog level “Debug.”
Trace. This is the most detailed setting. This level includes a complete 
record of system operations and activity. The Trace log level is 
recommended only for developers. Using this level causes a serious 
degradation of system performance and is not recommended. This log 
level is equivalent to the syslog level “Debug.”
Note
More detailed settings create larger log files and have a greater 
impact on system performance. 
Retrieval Method
Specifies where rolled over log files are stored and how they are retrieved for 
reading. See below for descriptions of the available methods.
Option
Description