jerome_itable Lv2Posted 11 Jan 2024 08:43
  
Here is a guide on accessing and viewing various event logs on your Sangfor Next-Generation Firewall (NGAF):

1. Access the NGAF Web Interface:

    Open a web browser and navigate to the NGAF's management IP address.
    Log in using your administrator credentials.

2. Locate the Log Management Section:

    The exact menu structure might vary depending on your NGAF version, but typically, you'll find log management under sections like:
        System > Logs
        Monitoring > Logs
        Security > Logs

3. Filter and View Logs:

    Event Categories: Most NGAFs categorize logs based on event types, such as:
        Firewall logs (traffic flow, blocked connections)
        Security logs (intrusion detection, malware events)
        Application control logs
        User activity logs
        System logs (configuration changes, device status)
    Filter Options: Use available filters to narrow down the logs based on:
        Time range
        Event severity
        Source IP/hostname
        Destination IP/hostname
        Application
        User
        Other criteria
    View Details: Click on individual log entries to view detailed information about the event.

4. Export Logs (Optional):

    Many NGAFs allow exporting logs in formats like CSV or TXT for further analysis or archiving.
    Check Export Options: Look for options like "Export" or "Download" within the log management section.

Common Event Types to Review:

    Firewall Logs: Blocked connections, allowed connections, traffic patterns.
    Security Logs: Intrusion attempts, malware detections, policy violations.
    Application Control Logs: Allowed and blocked applications, user activity.
    User Activity Logs: Authentication attempts, web access, resource usage.
    System Logs: Configuration changes, device status, performance metrics.

Additional Tips:

    Documentation: Refer to your NGAF's specific documentation for detailed instructions on log management and available log types.
    Best Practices:
        Regularly review logs to identify potential issues or security threats.
        Establish a log retention policy based on compliance requirements and storage constraints.
        Use log analysis tools to visualize trends and patterns in your network activity.
    Support: Contact Sangfor support if you encounter difficulties or need further guidance.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders