D-Link DFL-1000 [131/168] Event log message format

D-Link DFL-1000 [131/168] Event log message format
DFL-1000 User Manual
131
<date> <time> src=<source IP> dst=<destination IP> proto=<destination port>
msg="<protocol>, sport=<source port> <packet type> <action>"
Traffic log example messages
2002 Jun 19 15:35:09 src=192.168.2.1 dst=216.21.132.114 proto=80 msg="TCP,
sport=3125, SYN, ACCEPT"
2002 Jun 19 16:35:09 src=192.1.1.2 dst=2.3.4.5 proto=25 msg="UDP, sport=5214,
ACCEPT"
Event log message format
Event logs record management events and activity events. Management events include changes to the
system configuration as well as administrator and user logins and logouts. Activity events include system
activities, such as VPN tunnel establishment and URL blocking.
Each event log message records the date and time of the event and a description of the event. For
connections to the DFL-1000 for management and for configuration changes, the event log message also
includes the IP address of the management computer.
Management messages
All management event messages have the message type mgmt except for messages that record VPN
configuration changes, which have the type
vpn,mgmt
.
<date> <time> type=mgmt,msg="<management message>"
<date> <time> type=vpn,mgmt,msg="<vpn management message>"
Example management event log messages:
2002 Jun 19 15:35:10 type=mgmt,msg="User admin login successful at
192.168.2.2 by admin"
2002 Jun 21 20:35:09 type=mgmt,msg="Log&Report setting set successful at
192.168.100.111 by admin"
2002 Jun 22 15:35:09 type=vpn,mgmt msg="VPN-ipsec_auto auto add successful at
192.168.100.111 by admin"
Content filtering messages
Content filtering messages record when content blocking or URL blocking deletes a web page from a
content stream. Content filtering messages have the following format:
<date> <time> src=<source IP> dst=<destination IP> proto=<protocol>
msg="type=<Firewall event type> status=<status information> url=<url
blocked>"
Example content filtering messages:
2002 Jun 19 23:35:09 src=25.155.34.2 dst=192.168.100.105 proto=http
msg="type=Web-Filter status=BANWORDBLOCK url=www.filtered.com/index.htm"
2002 Jun 22 15:35:02 src=23.11.34.2 dst=192.168.100.105 proto=http
msg="type=Web-Filter status=URLBLOCK url=www.filtered.com/index.htm"
VPN tunnel monitor messages
VPN tunnel monitor log messages record when a VPN tunnel is started and stopped and also when keys
are renegotiated. VPN tunnel monitor messages have the following format:
<date> <time> type=vpn, msg=<description of the VPN tunnel status event>
Example VPN tunnel monitor message:
2002 Jun 19 15:35:09 type=vpn, msg="Initiator: tunnel 172.18.0.1/172.16.0.1
main mode phase I succeeded"

Содержание

Скачать