Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Logging, SNMP, and Telemetry

This topic explains how to enable system logging, SNMP, and Telemetry services on the SRX400 firewall series of your network.

After you have completed the system configuration of user accounts and authentication methods, you can enable system logging, SNMP, and telemetry on the device.

The SRX400 firewall series baseline configurations for logging, SNMP, and telemetry involves enabling essential logging for security events and system messages, basic SNMP for monitoring, and telemetry streaming for advanced analytics. This topic provides you the recommended minimal configurations.

System Logging and Security Logs

System Logs

Syslog and event logging ensure visibility into allowed or blocked flows, firewall health, and security events.

You can configure system logging to record system events, track configuration changes, and troubleshoot issues.

Basic logging captures system events, audit logs, and security policy actions. Start with local archiving and optional forwarding to a remote server.

This configuration below sets up local syslog archiving with structured data on SRX400 firewall and enables security event logging in event mode:

For log traffic information for a specific policy, see log (Security Policies).

Verify the logs configured:

Security Logs

For security logs (traffic logs) on the SRX400 firewall series, it is recommended to use the set security log mode stream command to send logs directly from the data plane to a remote syslog server through the revenue ports, avoiding overload on the Routing Engine.

  • Stream Mode—mode stream streams logs directly to external servers (example: set security log stream <name> host <IP>), ideal for high volume as it bypasses Routing Engine processing.
  • Event Mode—mode event or stream-event sends logs to the Routing Engine first, which can overwhelm the Routing Engine under high traffic; use set security log event-rate <limit> (example: 1500) to throttle.

Use the set security log mode stream and set security log report for on-box reporting to external servers. Stream mode supports UDP, TCP, and TLS protocols for secure transmission. You can configure up to 8 remote hosts to receive security logs simultaneously, providing redundancy and load distribution.

Best Practices

  • Use revenue ports (not re0:mgmt-0 management interface) for routing to the syslog server.
  • Formats: binary (compact, for JSA or STRM), sd-syslog (structured), syslog, protobuf, or welf.
  • Example for TLS-secured stream:
  • SDC or Cloud Logs: stream SYSLOG-STREAM requires a valid log plan in HPE Networking Security Director cloud-based (SDC).
  • Limits: Up to eight streams on SRX.

SNMP

SNMP provides device monitoring through MIBs. For more information, see SNMP MIB Explorer.

This baseline configuration below sets up basic SNMP monitoring on SRX400 firewall series with read-only community access, trap forwarding to a Network Management System (NMS), enables SNMPv2c (or SNMPv3 for enhanced security) with a community string and basic traps, and device identification details:

Verify the configuration using the show snmp statistics command.

Telemetry

Junos Telemetry enables you to stream device data from Juniper devices to external data collectors. This data can include information about traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behavior. Telemetry data is streamed over gRPC connections, and the connections can be initiated from a Juniper device or an external data collector.

For more information, see Junos Telemetry User Guide.

The sample baseline configuration below enables basic streaming, gRPC telemetry services, and configures a Junos Telemetry (JT) sensor on SRX400 firewall series:

Configuring Junos Telemetry

To enable this feature, you need to ensure:

  • Junos Telemetry Interface is available.

  • gRPC service is available.

  • OpenConfig for Junos OS Evolved is installed.

Configuration to enable telemetry to stream data to a collector as follows:

  • grpc: Protocol used for telemetry streaming.

  • remote-address: Telemetry collector server.

  • remote-port: Port used by the collector.

Configuration to set up telemetry sensors (example, interface statistics) as follows:

This configuration streams data like interface statistics, traffic counters, and error statistics. SRX400 firewall series supports advanced features like multiple gRPC servers and TLS.