Skybox version 8.5.400
25
Chapter 5
The syslog server in Skybox Appliance is preconfigured and is enabled by default.
Updates to the configuration files of the syslog server and the syslog log file
rotation are provided automatically (when necessary) as part of Skybox updates.
However, when updates are provided, you must restart the syslog server (on the
System tab, disable the syslog server and then enable it again) for it to start
using the updates.
In addition to the automatic updates, users can modify the files locally for local
changes:
›
The syslog configuration file is located at
/etc/syslog-ng/syslog-ng.conf
›
The log rotation file is located at
/etc/logrotate.conf
Note: If you modify the files locally, you must also restart the server afterwards.
Where are the logs stored?
When the syslog server is enabled, new log files are stored in one of the
following locations (depending on the type of log):
•
/var/log/syslog-ng/new
•
/var/log/firewall_assurance/change_logs/new
The logs are kept for 48 hours in the new directory, and are then archived for 3
more days in the parallel old directory:
•
/var/log/syslog-ng/old
•
/var/log/firewall_assurance/change_logs/old
What are the log files named?
A separate log is generated for each device from which logs are received. The file
names have the following format:
•
New logs:
<host name | IP address>_<time of creation>.log
•
Archived logs:
<host name | IP address>_<time of creation>.zip
How can the logs be imported to Skybox?
Device logs can be imported using the following tasks, depending on what
information you are looking for:
›
Change Tracking Events – Syslog Import
›
Traffic Events – Syslog Import
At a minimum, you need the following information (in the task) to import the
logs:
Customizing the syslog server