Modifying the log settings and levels
07/12/2022
126 People found this article helpful
307,282 Views
Description
This KB provides instructions on how to customise the log settings and levels in order to optimize reporting and performance.
Cause
The logging on UTM appliances can be quite intensive. In some instances too much information may be recorded and this may overwhelm the appliance. It is important to gauge which information is required and how often this information is refreshed. The Log Monitor may not need to display certain events or their refresh interval may not need to be so frequent.
The log settings offer different options to reduce the logging intensity and to reduce the logging frequency.
Resolution
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
These options will assist in setting the correct logging level and intensity. To change the log settings go to Device / Log / Settings
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711832396.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Templates
The Template option will allow different log category templates to be selected
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711781157.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Log Monitor
The Log Monitor can be found under Monitor|Logs |System Logs
If an event does not need to appear in the Log Monitor it can be disabled. The event count will show how often the event occurs. Events which occur frequently, and fill up the logs, can be disabled.
The log monitor has limited storage space. Frequently occuring events will overwrite the oldest events. More relevant events could be overwritten by frequently occuring events. For this reason it is advisable to disable or reduce the refresh interval of such events.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711888500.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
The refresh interval can be increased or reduced by configuring an event
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711443377.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
The default value is 0 but this should be changed to at least 60 or a higher value, as required
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711223193.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Events can also be excluded from the Log Monitor by using the quick disable option. This appears in the log monitor by hovering over a particular event. Clicking on the slider excludes and removes the event from the log monitor.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711120400.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Logging level
The priority level needs to match or be set higher than the logging level in order for events to be recorded. If the logging level is set to inform and the priority level set to debug then no events will be recorded.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711844762.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Event logging is intensive and uses a considerable amount of processing time. If Sonicwall reporting/management solutions are not being used, or if syslog is not required, then the the logging level should be set to Notice. Sufficient information will still be recorded for troubleshooting and information purposes. If the level needs to be changed to debug then this should only be selected for a limited time. The level should be reset to Notice, or higher, once the required information has been retrieved.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711394364.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Exporting the log
It is possible to export all the logs directly from the appliance. There is no need to change the GUI viewing interval. This option is solely for the purpose of the Log Monitor display. The export option retrieves all events from the internal storage and allows them to be exported in three different formats. The CSV option is the only option which should be used; especially when forwarding the logs to support. It is important that only log files in the CSV format are uploaded to support cases.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220711325946.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Log settings
Log settings are located under Manage>Log Settings>Base Setup
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712714821.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
To import a template click on Import Template
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712997705.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
The minimal template should serve most purposes and help reduce unnecessary logging on the firewall.
The logging levels and event settings can be configured using the options below. Please refer to the SonicOS 7.x section for more information relating to logging levels.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712988198.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
The refresh interval can be changed similarly to SonicOS 7.x
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712480539.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Log Monitor
To exclude events from the Log Monitor use the disable button
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712625356.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Exporting the log is done in a similar fashion to SonicOS 7.x. The CSV option should be selected here also.
![Image](https://sonicwall.rightanswers.com/portal/app/portlets/results/onsitehypermedia/090220712715206.png?linkToken=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJzb25pY3dhbGwiLCJleHAiOjE3NTM0OTkzNjAsImlhdCI6MTcyMTk2MzM2MH0.lf0eVeFpwSLnJwt7Xg0fT8rn1ShaeAAUcOTfec9J_x4)
Related Articles
Categories