For all traffic that matched a quarantine zone access rule, the Sensor can forward the details to a syslog server. You can use these details for analysis and reporting purposes. For example, you can view the details of hosts that attempted to access a critical network when in quarantine. You can also log the packets that matched the quarantine zone access rules.
To forward the matched details to a syslog server, you must complete the following:
If you want the Sensor to send the logged details directly to the syslog server, ensure that the configured syslog server is accessible to the Sensor’s management port.
Note
Only NS-series Sensors can directly send logs to a syslog server.
Alternatively, if you want the Sensor to send the details through the Manager, then the Manager must be able to communicate to the syslog server. In this case, the Sensor forwards the logs to the Manager, which formats and converts them to syslog messages and sends them to the configured syslog server. You can then view the log from a third-party syslog application.
Enable syslog forwarding for Quarantine at the admin domain level.
Note
For syslog forwarding, the admin domains have the option to include the logs from the corresponding child domains.
Enable syslog forwarding for Quarantine at the Sensor level. When you enable at the Sensor level, you can specify the conditions for logging. For example, you can specify whether to log permitted traffic or denied traffic. You can also specify if traffic should be logged only if specified in the quarantine zone access rule.
At both the domain and Sensor levels, the process of configuring the syslog server details is similar between Firewall Policies, and Quarantine. However, the configuration for Firewall Policies is different from Quarantine. That is, even if you are using the same syslog server for all these features, you must configure them separately for Firewall Policies and Quarantine. You can also configure different syslog servers for Firewall Policies and Quarantine.