Click the Manager tab.
From the Domain drop-down list, select the domain you want to work in.
Select Setup → Notification → Firewall Access Events.
Specify the domain-level syslog details in the corresponding fields.
Syslog server details for Firewall Access Events.png)
Option
Definition
Enable Syslog Notification
If you select Yes, the details of the traffic that matched an access rule is forwarded to a syslog server. You can also configure the details now and enable it at a later time.
Admin Domains
Current — The syslog configuration applies only to the current domain. This is always enabled for the current domain.
Children — The syslog configuration applies to child domains as well. You can also modify this syslog configuration at a child domain if required.
Server Name or IP Address
Enter the syslog server name or its IP (IPv4 or IPv6) address. If you specify the syslog server name:
The Manager uses the DNS servers configured in its TCP/IP properties.
If you choose the Sensor to forward the logs to a syslog, then the Sensor uses the DNS servers that you configured in the Name Resolution page for the Sensor.
Note
The length of server name has been increased to support up to 255 characters from 40 characters.
Port
Enter the communication port number on the target server which is authorized to receive syslog messages. The standard port for syslog, which is 514, is pre-filled in the field. If you are using a non-standard port, then replace 514 with that number.
Facility
Lists the syslog prioritization values.
By default, the syslog messages forwarded to a syslog server are of Security authorization prioritization value.
Severity
Lists the syslog priority values.
By default, the syslog messages forwarded to a syslog server are of Debug severity.
Message Body
Optionally, customize the default syslog message. There are two types:
System Default — The default message is a quick summary for easy recognition. A default message reads (visible in the Message field of the Customize Syslog Forwarder Message page):
"$IV_SENSOR_NAME$$IV_ACL_ID$$IV_ACL_ACTION$$IV_APPLICATION_PROTOCOL$$IV_SOURCE_IP$$IV_SOURCE_PORT$ $IV_DESTINATION_IP$$IV_DESTINATION_PORT$"Customized — You can customize the message after you successfully save the syslog configuration details. Click Test Connection to view the option to edit the default message.
Important
Till 11.1 Update 4 release, all Syslog notifications generated from the Manager UI were prefixed with the timestamp format MMM DD HH:MM:SS. From the 11.1 Update 5 release onwards, along with this timestamp, additional timestamp with format [MMM DD, YYYY HH:MM:SS] is appended to each Syslog notification from the Manager for auditing purposes. This timestamp update is independent of the syslog variables (default or customized) used to configure syslog notifications.
As a user, you need to update the Syslog parsing logic in the third-party Syslog application(s) in use to avoid any timestamp conflicts in the Syslog notifications.
Test Connection
Checks if the Manager is able to send logs to the syslog server. Check your syslog server if it has received the test message from the Manager. If not, check the syslog server name or IP address that you had provided. Ping the syslog server from the Manager server to see if the Manager is able to reach the syslog server. If you plan to configure NS-series Sensors to directly send the messages to the syslog server, ping the syslog server from the Sensor's CLI. This option is available in the Firewall Logging page.
Note
You can use the test connection feature, even if you have set Enable Syslog Forwarding? to no.
Save
Saves the syslog configuration changes in the Manager database. Once you click Save, you will be able to customize the message format sent to the syslog server.
Note
If you have modified the syslog configuration, then do a configuration update of the Sensors for the changed settings to take effect.
Click Save.
Note
Once you click Save, you will be able to customize the message format sent to the syslog server.
Do a Configuration Update for the Sensors for the notification settings to take effect.
Note
Use the
show acl statscommand in the Sensor's CLI to see the count of ACL logs sent through the Manager.
Enable rule match notification
- Published on Oct 5, 2026
- 3 minute(s) read
Was this article helpful?