The SSL Session Log module generates connection event logs for each Network Security SSL session detected on the SSL interception-enabled port pair on the appliance. The SSL Session Log collects logs about all the SSL flows generated by the Network Security appliance. You can view details of the SSL flows to help you identify suspicious trends or patterns in SSL interception traffic observed by the Network Security appliance. You can uniquely identify the SSL flow activity that needs to be inspected by SSL interception on the Network Security appliance. Information about the SSL flows can help you to identify whether the connection was decrypted, whitelisted, or blocked due to an attack seen in the decrypted content. Each SSL flow is a new entry in the log file and formatted in ASCII text.
The SSL Session Log module listens on the server port to check for connection log requests on the Network Security appliance. You can configure the maximum number of archived log files stored on the appliance. The rotation of log files removes the oldest archived log file from the Network Security appliance. The log rotation allows the appliance to rename the current log file and set up a new log file to capture SSL flows. The SSL Session Log module is disabled by default.
Task list for managing the SSL session log module
Complete the steps for managing the SSL Session Log module in the following order.
Verify that SSL interception is configured and enabled. For details about how to enable SSL interception, see Enabling or disabling SSL interception using the Web UI or Enabling or disabling SSL interception using the CLI.
Enable the ADD Product Series appliance to collect statistics about traffic from the SSL flows. For details about how to start collecting SSL flow statistics, see Enabling or disabling SSL session logging using the CLI.
Start collecting statistics for SSL interception traffic on the Network Security appliance. For details about how to start collecting statistics on SSL interception traffic, see Enabling or disabling SSL Flow statistics collection for SSL interception using the CLI.
Enable a session log field for each connection event. For details about how to enable the session log field, see Enabling or disabling the session log fields using the CLI.
Configure the maximum number of archived log files you want to store on the appliance. For details about how to configure the maximum number archived log files, see Configuring the number of archived log files using the CLI.
View the connection event log details about traffic from the SSL flows that are being inspected or not inspected. For details about how to view the connection event log details, see Viewing the Connection Event Logs.