Logging, SNMP, and Telemetry
This topic explains how to enable system logging, SNMP, and Telemetry services on the SRX400 firewall series of your network.
After you have completed the system configuration of user accounts and authentication methods, you can enable system logging, SNMP, and telemetry on the device.
The SRX400 firewall series baseline configurations for logging, SNMP, and telemetry involves enabling essential logging for security events and system messages, basic SNMP for monitoring, and telemetry streaming for advanced analytics. This topic provides you the recommended minimal configurations.
System Logging and Security Logs
System Logs
Syslog and event logging ensure visibility into allowed or blocked flows, firewall health, and security events.
You can configure system logging to record system events, track configuration changes, and troubleshoot issues.
Basic logging captures system events, audit logs, and security policy actions. Start with local archiving and optional forwarding to a remote server.
This configuration below sets up local syslog archiving with structured data on SRX400 firewall and enables security event logging in event mode:
[edit] set system syslog file messages kernel info set system syslog file messages any notice set system syslog file messages authorization info set system syslog file messages pfe info set system syslog file messages archive world-readable set system syslog file security interactive-commands any set system syslog file security archive world-readable set security log mode stream commit
For log traffic information for a specific policy, see log (Security Policies).
Verify the logs configured:
show security logSecurity Logs
For security logs (traffic logs) on the SRX400 firewall series, it is recommended to use
the set security log mode stream command to send logs directly from the
data plane to a remote syslog server through the revenue ports, avoiding overload on the
Routing Engine.
- Stream Mode—
mode streamstreams logs directly to external servers (example:set security log stream <name> host <IP>), ideal for high volume as it bypasses Routing Engine processing. - Event Mode—
mode eventorstream-eventsends logs to the Routing Engine first, which can overwhelm the Routing Engine under high traffic; useset security log event-rate <limit>(example: 1500) to throttle.
Use the set security log mode stream and set security log
report for on-box reporting to external servers. Stream mode supports UDP, TCP,
and TLS protocols for secure transmission. You can configure up to 8 remote hosts to
receive security logs simultaneously, providing redundancy and load distribution.
set security log source-address 10.10.1.1 set security log stream SYSLOG-STREAM severity info set security log stream SYSLOG-STREAM format syslog set security log stream SYSLOG-STREAM host 10.5.0.2 set security log stream SYSLOG-STREAM host port 514
Best Practices
- Use revenue ports (not re0:mgmt-0 management interface) for routing to the syslog server.
- Formats:
binary(compact, for JSA or STRM),sd-syslog(structured),syslog,protobuf, orwelf. - Example for TLS-secured stream:
set security log mode stream set security log format sd-syslog set security log source-interface <interface> set security log stream <name> host <IP> set security log transport protocol tls
- SDC or Cloud Logs:
stream SYSLOG-STREAMrequires a valid log plan in HPE Networking Security Director cloud-based (SDC). - Limits: Up to eight streams on SRX.
SNMP
SNMP provides device monitoring through MIBs. For more information, see SNMP MIB Explorer.
This baseline configuration below sets up basic SNMP monitoring on SRX400 firewall series with read-only community access, trap forwarding to a Network Management System (NMS), enables SNMPv2c (or SNMPv3 for enhanced security) with a community string and basic traps, and device identification details:
[edit] set snmp community public authorization read-only set snmp trap-group trap-to-server targets 192.0.2.1 # Replace with your NMS IP set snmp trap-group trap-to-server version v2 set snmp location "SRX400-DC1" set snmp contact admin@example.com commit
Verify the configuration using the show snmp statistics command.
Telemetry
Junos Telemetry enables you to stream device data from Juniper devices to external data collectors. This data can include information about traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behavior. Telemetry data is streamed over gRPC connections, and the connections can be initiated from a Juniper device or an external data collector.
For more information, see Junos Telemetry User Guide.
The sample baseline configuration below enables basic streaming, gRPC telemetry services, and configures a Junos Telemetry (JT) sensor on SRX400 firewall series:
Configuring Junos Telemetry
To enable this feature, you need to ensure:
-
Junos Telemetry Interface is available.
-
gRPC service is available.
-
OpenConfig for Junos OS Evolved is installed.
Configuration to enable telemetry to stream data to a collector as follows:
set system services extension-service request-response grpc clear-text port 50051set telemetry-streaming server COLLECTOR-1 remote-address 10.10.10.20set telemetry-streaming server COLLECTOR-1 remote-port 50051
-
grpc: Protocol used for telemetry streaming. -
remote-address: Telemetry collector server. -
remote-port: Port used by the collector.
Configuration to set up telemetry sensors (example, interface statistics) as follows:
set telemetry-streaming sensor-group INTERFACE-STATS sensor /interfaces/interface/state/set telemetry-streaming sensor-group INTERFACE-STATS export-to COLLECTOR-1
This configuration streams data like interface statistics, traffic counters, and error statistics. SRX400 firewall series supports advanced features like multiple gRPC servers and TLS.