The SonicWall SMA 1000 series supports forwarding log data to a remote syslog server for centralized monitoring. However, not all log categories are forwarded via syslog. Management audit logs — which record administrative actions taken within the AMC — are not included in the syslog feed. This is by design. This article explains which log types are forwarded, which are not, and how to access the full audit trail.
|
Log Category |
Forwarded to Syslog |
Notes |
|
User login / logout events |
Yes |
Includes username, realm, source IP, timestamp, and session duration. |
|
VPN tunnel connection events |
Yes |
Includes tunnel type (Connect Tunnel, Mobile Connect), assigned IP. |
|
Access policy evaluation |
Yes |
Includes allow/deny decisions and matched policy rules. |
|
Management audit logs |
No |
Administrative actions (configuration changes, user management) are logged only in the AMC and on-appliance log files. |
|
System events |
Yes |
Includes HA failover, firmware updates, certificate expiration warnings. |
|
EPC evaluation results |
Yes |
Includes pass/fail per EPC policy rule per user session. |
To view the full management audit log, use one of the following methods:
Important: The management audit log path on the filesystem may differ between firmware versions. If the path above does not exist, check /var/log/audit/ or consult the SMA1000 administration guide for your firmware version. The AMC dashboard method is the most reliable way to access these logs regardless of firmware version.