Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 734
 
25-14
Cisco IronPort AsyncOS 7.5.7 for Web User Guide
Chapter 25      Logging
Working with Log Subscriptions
Step 13
Submit and commit your changes.
Step 14
If you chose SCP as the retrieval method, the appliance displays an SSH key to you must place on the 
SCP server host. 
Deleting a Log Subscription
To delete a log subscription:
Step 1
Navigate to the System Administration > Log Subscriptions page.
Step 2
Click the icon under the Delete column for the log subscription you want to delete.
Step 3
Submit and commit your changes.
SCP on Remote 
Server
(SCP Push)
This method periodically pushes log files using the secure copy protocol to an 
SCP server on a remote computer. This method requires an SSH SCP server on 
a remote computer using the SSH1 or SSH2 protocol. The subscription requires 
a user name, SSH key, and destination directory on the remote computer. Log 
files are transferred based on a rollover schedule set by you.
When you choose this method, you must enter the following information:
  •
Maximum time between file transfers
  •
Protocol to use for transmission, either SSH1 or SSH2
  •
SCP server hostname
  •
Directory on SCP server to store the log file
  •
Username of a user that has permission to connect to the SCP server
Choose whether or not to enable host key checking. 
Syslog Push
This method sends log messages to a remote syslog server. This method 
conforms to RFC 3164. The appliance uses port 514.
When you choose this method, you must enter the following information:
  •
Syslog server hostname
  •
Protocol to use for transmission, either UDP or TCP
  •
Facility to use with the log
You can only choose syslog for text-based logs.
Note
Syslog messages greater than 1024 bytes are truncated. Access logs and 
W3C access logs with many custom variables, especially of variable 
length, might exceed the 1024 byte limit. 
Table 25-4
Log Transfer Protocols (continued)
Retrieval Method
Description