Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Pacheco
Explorer
Jump to solution

Log Supression

Hello,

 

Is it possible to disable log supression for one specific rule? If so, how can i do it? If not, how can i disable it globally?

 

Best regards.

Pedro Pacheco

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

I'm going to assume you are referring to Log Suppression as utilized by Threat Prevention logs and also logging for Inspection Settings (formerly part of TP), and not Session Logging which is only for Access Control policy logs.  The answer is quite complicated, but thankfully already covered in my 2021 IPS/AV/ABOT Video Series.  Log Suppression cannot be disabled on a per-rule basis, only on a per-gateway basis via the logsup_none kernel variable as mentioned in the SKs below.  But be warned that doing so may significantly increase the logging load on both your gateway and logging server (which is usually the SMS):

suppression.png

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

4 Replies
_Val_
Admin
Admin

Can you please give an example of a rule you are talking about? FW only or Application Control?

Timothy_Hall
Champion
Champion

I'm going to assume you are referring to Log Suppression as utilized by Threat Prevention logs and also logging for Inspection Settings (formerly part of TP), and not Session Logging which is only for Access Control policy logs.  The answer is quite complicated, but thankfully already covered in my 2021 IPS/AV/ABOT Video Series.  Log Suppression cannot be disabled on a per-rule basis, only on a per-gateway basis via the logsup_none kernel variable as mentioned in the SKs below.  But be warned that doing so may significantly increase the logging load on both your gateway and logging server (which is usually the SMS):

suppression.png

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
_Val_
Admin
Admin

Master Tim strikes again 🙂

0 Kudos
Pacheco
Explorer

Thank you Tim! That is exactly what i needed, I'm aware of the implications of disabling supressed logs, i will only disable it for troubleshooting.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events