Technical Documentation

IDP Logs and Reports in NSM Task Summary

IDP devices generate logs about device status based on built-in criteria and about security events based on the security policy notification settings. These logs are automatically sent to the NSM GUI server and can be viewed in the NSM log viewer.

IDP administration includes the following log-related tasks:

  • Viewing device status, logs, and reports.
  • Viewing attack logs and reports.
  • Viewing application usage logs and reports.
  • Configuring interface aliasing, if you want to identify IDP traffic interfaces by name in logs and reports.
  • Configuring log suppression, if you want to reduce the number of identical log files.
  • Configuring communication with an SNMP or syslog server, if you use external log programs to view alerts or analyze or archive log data.
  • Ensuring collection of packet data in NSM logs is enabled, if you want to drill into packet data from NSM logs.

Note: To avoid issues with reports, we highly recommend that you synchronize the network clocks for all devices to the same NTP server. For example, the network clocks for all IDP appliances and NSM clients should be synchronized to the NTP server specified in the NSM configuration.


Published: 2010-01-12