You can view the connection event logs using the Network Security appliance CLI:
The Network Security appliance displays the connection event log details about SSL flows based on SSL interception traffic it observes. Viewing log details on SSL flows can help you to identify specific trends or patterns in SSL interception traffic.
The following table describes the log fields that are tracked by the Network Security appliance for each connection event:
Field | Description |
|---|---|
Date | Date that the connection event is logged. |
Time | Time that the connection event is logged. |
c_ip | IP address of the client. |
c_port | Port number of the client. |
s_ip | IP address of the server. |
s_port | Port number of the server. |
cs_bytes | Client-side bytes transferred during the connection and logged. |
rs_bytes | Server-side bytes transferred during the connection and logged. |
cs_tls_version | TLS version required for client-side connections. |
rs_tls_version | TLS version required for server-side connections. |
cs_cipher_suite | Cipher suite associated with client-side connections. |
rs_cipher_suite | Cipher suite associated with server-side connections. |
rs_cert_common_name | Common name of the server-side certificate. |
action | Whether the connection was decrypted, whitelisted, or blocked due to an attack seen in decrypted content. |
s_site_name | Server name identification (SNI) sent by the client or server |
error | Types of error codes for connection events:
|
Prerequisites
Administrator access to the Network Security appliance.
Verify that SSL interception is configured and enabled. For details about how to enable SSL interception, see Enabling or disabling SSL interception using the Web UI of Enabling or disabling SSL interception using the CLI.