Use the CLI commands in this section to enable or disable the Network Security appliance to collect statistics about traffic from the SSL flows.
Note
You can enable or disable SSL session logging only using the CLI.
Prerequisites
Administrator access to the Network Security appliance.
Verify that SSL interception is configured and enabled. For details about how to enable SSL interception, see Enabling or disabling SSL interception using the Web UI or Enabling or disabling SSL interception using the CLI.
The "Status" line displays "enabled" to indicate that the SSL session log module can generate logs on the Network Security appliance. The "Listening State" line displays "Ready" to indicate that the SSL session log mechanism is ready to process requests.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the collection of statistics.
hostname (config) # session-logger enable
Verify that the module is ready to collect statistics.
hostname (config) # show session-logger statusStatus : enabled Listening State: Ready Module Name : Status ------------------------ ssl : OFF
hostname (config) # show session-logger status Status : disabled Listening State: Ready(but admin disabled)
The "Status" line displays "disabled" to indicate that the SSL session log process cannot generate logs on the Network Security appliance. The "Listening State" line displays "Ready (but admin disabled)" to indicate that the SSL session log mechanism has been stopped by the administrator.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disable the collection of statistics.
hostname (config) # no session-logger enable
Verify that the module is not collecting statistics.