ScreenOS:Syslog Server - Facilities

Information

Using a syslog server provides a means to collect, analyze, and store device logs off-box in the event the source device fails or the original logs are compromised in some fashion, whether intentionally or via error. Most syslog servers also provide a means of searching, reporting, and alerting which greatly assists in the administration of the firewall.

The facilities setting controls the details of what gets logged and may require that you review the Juniper documentation to ensure your local logging requirements are being met. The facility local2 is usually sufficient to provide good coverage of useful information.

NOTE: You will need to change 'Syslog_Server_IP' to the appropriate IP address of the syslog server used in your organization.

Solution

You may navigate to the following ScreenOS menu location: Configuration > Report Settings > Syslog

See Also

https://www.juniper.net/techpubs/en_US/screenos6.3.0/information-products/pathway-pages/screenos/index.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), 800-53|AU-12

Plugin: Juniper

Control ID: 94f7abbc01cc770761c5fe13001191f9294546dbe327a3b4d95899a7eb42db5e