The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enabling or disabling the session log fields using the CLI

Prev Next

Use the CLI commands in this section to enable or disable a session log field for each connection event that is logged in to the Network Security appliance to detect SSL interception traffic. You enable the session log separately.

Note

You can enable or disable a session log field only using the CLI. The session log fields are disabled by default.

Prerequisites

To enable the session log fields for each connection event:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Enable each session log field you want to include in the file for SSL interception traffic.

    hostname (config) # session-logger ssl field <log_fieldName> enable

    where <log_fieldName> is the log field you want to log to the appliance.

    Valid session log fields are:

    • cs_cipher_suite—Cipher suite associated with client-side connections.

    • rs_cipher_suite—Cipher suite associated with server-side connections.

    • rs_cert_status—Server-side certificate that is logged.

    • cs_bytes—Client-side bytes transferred during the connection and logged.

    • rs_bytes—Server-side bytes transferred during the connection and logged.

    • time_taken—Date and time that the connection event is logged.

  3. Verify the status of the session log fields for SSL interception traffic.

    hostname (config) # show session-logger ssl config

Example

This example shows how to enable three session log fields for SSL interception traffic.

hostname (config) # session-logger ssl field cs_bytes enable
hostname (config) # session-logger ssl field cs_cipher_suite enable
hostname (config) # session-logger ssl field rs_cipher_suite enable
hostname (config) # show session-logger ssl config
Feature Status   :  enabled
Max File Rotation Limit : 5

Field Name       : Status
------------------------
cs_bytes        : ONcs_cipher_suite : ON
rs_bytes         : OFF
rs_cert_status   : OFF
rs_cipher_suite : ON
time_taken       : OFF
To disable the session log fields for each connection event:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Disable a session log field.

    hostname (config) # no session-logger ssl field <log_fieldName> enable

    where <log_fieldName> is the log field you want to log to the appliance.

    Valid session log fields are:

    • cs_cipher_suite—Cipher suite associated with client-side connections.

    • rs_cipher_suite—Cipher suite associated with server-side connections.

    • rs_cert_status—Server-side certificate that is logged.

    • cs_bytes—Client-side bytes transferred during the connection and logged. l rs_bytes—Server-side bytes transferred during the connection and logged.

    • time_taken—Date and time that the connection event is logged.

  3. Verify the status of the session log fields for SSL interception traffic.

    hostname (config) # show session-logger ssl config

Example

This example shows how to disable one session log field for SSL interception traffic.

hostname (config) # no session-logger ssl field cs_cipher_suite enable
hostname (config) # show session-logger ssl config
Feature Status :  enabled
Max File Rotation Limit : 5

Field Name      : Status
------------------------
cs_bytes        : ON
cs_cipher_suite : OFF
rs_bytes        : OFF
rs_cert_status  : OFF
rs_cipher_suite : ON
time_taken      : OFF