This receiver type is discussed further below in
Section 2.3.6, “Mail Alerting”
.
2.3.4. The Memory Log Receiver (Memlog)
Overview
The
Memory Log Receiver
(also known as
Memlog
) is a NetDefendOS feature that allows logging
direct to memory in the NetDefend Firewall instead of sending messages to an external server.
These messages can be examined through the standard user interfaces.
Memlog has Limited Capacity
Memlog memory available for new messages is limited to a fixed predetermined size. When the
allocated memory is filled up with log messages, the oldest messages are discarded to make
room for newer incoming messages. This means that MemLog holds a limited number of
messages since the last system initialization and once the buffer fills they will only be the most
recent. This means that when NetDefendOS is creating large numbers of messages in systems
with, for example, large numbers of VPN tunnels, the Memlog information becomes less
meaningful since it reflects a limited recent time period.
Memlog Timestamps
The timestamp shown is Memlog console output is always the local system time of the firewall.
This is different from the timestamp on log messages sent to external log Receivers which are
always timestamped with GMT time.
Disabling and Enabling Memlog
A single
Memory Log Receiver
object exists by default in NetDefendOS and memlog is therefore
enabled by default. If logging to memlog is not required then the
Memory Log Receiver
object can
be deleted and this type of logging will not occur. To re-enable memlog, add back the
Memory
Log Receiver
object to the configuration. Only one instance of the
Memory Log Receiver
can exist
at any one time.
2.3.5. The Syslog Log Receiver
Overview
Syslog
is a standardized protocol for sending log data although there is no standardized format
for the log messages themselves. The format used by NetDefendOS is well suited to automated
processing, filtering and searching.
Although the exact format of each log entry depends on how a Syslog receiver works, most are
similar. The way in which logs are read is also dependent on how the syslog receiver works.
Syslog daemons on UNIX servers usually log to text files, line by line.
Message Format
Most Syslog recipients preface each log entry with a timestamp and the IP address of the
machine that sent the log data:
Chapter 2: Management and Maintenance
89
Summary of Contents for NetDefendOS
Page 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Page 32: ...Chapter 1 NetDefendOS Overview 32 ...
Page 144: ...Chapter 2 Management and Maintenance 144 ...
Page 284: ...Chapter 3 Fundamentals 284 ...
Page 392: ...Chapter 4 Routing 392 ...
Page 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Page 420: ...Chapter 5 DHCP Services 420 ...
Page 573: ...Chapter 6 Security Mechanisms 573 ...
Page 607: ...Chapter 7 Address Translation 607 ...
Page 666: ...Chapter 8 User Authentication 666 ...
Page 775: ...Chapter 9 VPN 775 ...
Page 819: ...Chapter 10 Traffic Management 819 ...
Page 842: ...Chapter 11 High Availability 842 ...
Page 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Page 879: ...Chapter 13 Advanced Settings 879 ...