Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mille
Participant

Logging with limited log samples?

Hi Mate,

Do you know any way to enable limited logging on an access rule, say 5% rule hits are logged and the rest is not logged?

Why?
A typical access rule will have log enabled and all matches for that rule will be logged.
Some types of trafic (like DNS, NTP, SNMP and NETBIOS) will generate a lot of hits and you may opt to disable log for this 'noise'.
However that will leave you 'blind' both in terms of the direct trafic and in terms of statical reporting and other data processing.

BR Mille

0 Kudos
3 Replies
Amir_Senn
Employee
Employee

There is no partial logging.

Best suggestions I can offer are:

a. You can create build in filter that will filter unwanted logs from results

b. Identify all the features of the noisy logs and instead of the current rule, replace action with layer. Under this layer, create the first rules with a combo of source, destination and service and don't log those. If you keep it well defined I don't think you should have issues.

Kind regards, Amir Senn
Mille
Participant

Amir Senn, Thank you for the suggestions. I was hoping for some kind of partial logging.

/Mille

0 Kudos
Amir_Senn
Employee
Employee

You can also change the tracking options on layer suggestion to be session instead of connection. Should lower number of all logs that match the rule.

Kind regards, Amir Senn
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events