Defining log fields included in logs forwarded by SMC
- Article Number: 000010010
- Products: NGFW Security Management Center
- Version: 6.5, 6.4, 6.3, 6.2, 6.1, 6.0, 5.10
- Last Published Date: March 04, 2019
NGFW Security Management Center can forward logs to external hosts in different formats. A select set of default log fields are forwarded, but these can be modified when logs are forwarded in CSV, XML or ESM format. Starting from SMC version 6.5.2 it is possible to modify custom fields in CEF and LEEF formats.
Note Other log export formats (Netflow v9 and IPFIX) only offer a fixed log field selection that cannot be edited.
To find out more information and how to resolve this issue, see the steps below.
Customizing log fields for CSV or XML log forwardingThe parameter SYSLOG_CONF_FILE in the <installation directory>/data/LogServerConfiguration.txt file defines the template used when logs are forwarded. The template tells the Log Server what fields to include in the forwarded logs.
If the template does not exist, cannot be accessed due to incorrect file permissions, or the SYSLOG_CONF_FILE parameter is not defined, then Log Server uses the exportable field list defined in the relevant datatype XML file in <installation directory>/data/fields/datatypes to select what fields are forwarded.
There are default templates in the /data/fields/syslog_templates folder which can be used as a starting point.
Important All the default templates in the syslog_templates folder are overwritten during an SMC upgrade. It is recommended you duplicate one of the default templates and point the SYSLOG_CONF_FILE to the custom template so your changes are not lost during upgrade.
The SYSLOG_CONF_FILE parameter should be added to LogServerConfiguration.txt to point to the required template file:
Customizing log fields for ESM log forwardingTo modify the field selection for logs forwarded as ESM, configure the exportable fields in the esm_syslog_conf.xml syslog template:
Modifying custom log fields for CEF and LEEF log forwardingBoth CEF and LEEF formats include few customizable fields. With SMC 6.5.2 version and higher it is possible to change log field included on customizable fields.
Important All the default templates are overwritten during an SMC upgrade and therefore it is suggested to edit a custom file.
Related InformationFor a full list of product documents, see Documentation.