The page has been translated by Gen AI.

Firewall Logging

To save Firewall logs, you must first create a bucket in Object Storage to save the logs and set the bucket as the log repository in Firewall Logging, then set up log saving on the Firewall details page, and the Firewall logs will be saved in the Object Storage bucket.

To save the firewall log, set it up in the following order.

  1. You can create a bucket in Object Storage to store Firewall logs or use an existing bucket. To create a bucket, refer to Object Storage creation.
  2. To set this bucket as the log repository for Firewall Logging, see Using Firewall Logging log repository.
  3. To set the log storage to use in the Firewall detailed inquiry, please refer to Firewall Log Storage Usage.

Firewall Logging Configure log storage settings

To set the log saving status of Firewall to use, you must first set the log storage in Firewall Logging.

Reference
To set up Firewall Logging, an Object Storage bucket for logging is required. First, create a bucket in the Object Storage service. For more detailed information, please refer to Object Storage creation.

To enable the Firewall Logging log storage, follow the procedure below.

  1. Click on the menu for all services > Management > Network Logging > Firewall Logging. It moves to the Firewall Logging list page.
  2. Firewall Logging list page, click the top Log Storage Settings button. Move to the Log Storage Settings popup window.
  3. Log Storage Settings In the popup window, select the Log Storage Bucket. Once the bucket is selected, the Log Storage Path will be displayed.
  4. In the Log Storage Settings popup window, check the Log Storage Bucket and Log Storage Path, then click the OK button.
  5. Check the message in the Notification pop-up window, then click the Confirm button.
Notice
After setting the log storage, you must set the log storage to Use on the Firewall Details page for logging to start. For more detailed information, please refer to Firewall log storage usage.

Firewall Logging list inquiry

If you set the Firewall Logging log storage bucket, you can retrieve the Firewall Logging list.

To view the Firewall Logging list, follow these steps.

  1. Click on the menu for all services > Management > Network Logging > Firewall Logging. It moves to the Firewall Logging list page.
  2. Firewall Logging list page, please check the resources in use and the log storage target.
    DivisionDetailed Description
    Resource IDFirewall ID
    Save TargetFirewall Name
    Save Registration TimeFirewall Log Storage Registration Time
    Table. Firewall Logging list items
    Note
    After setting the Firewall Logging log storage, you must set the log storage to use in the Firewall detail inquiry for log storage to start. For more detailed information, please refer to Using Firewall Log Storage.

Firewall Logging Check detailed contents

Please check the detailed contents of the saved Log based on the following contents.

Saved log example: 2024-10-11T11:23:43,deny,0,17,4.1.1.100,45499,192.168.10.10,53

DivisionDescription
2024-10-11T11:23:43The date and time when the log occurred (2024-10-11, 11:23:43)
denyaction (deny / accept)
0The Rule ID (Policy ID) where the log occurred on the firewall
17IP Protocol ID
  • 1: ICMP
  • 6: TCP
  • 17: UDP
4.1.1.100Source IP
45499Departure Port
192.168.10.10Destination IP
53Destination Port
Table. Log detail information items

Firewall Logging Disable log storage setting

You can set the log storage to not used in Firewall Logging.

To set the log storage to not used for Firewall Logging, follow the next procedure.

  1. Click on the menu for all services > Management > Network Logging > Firewall Logging. It moves to the Firewall Logging list page.
  2. Firewall Logging list page, click the top Log Storage Settings button. Move to the Log Storage Settings popup window.
  3. In the 로그 저장소 설정 popup window, select 로그 저장소 버킷 as 미사용 and click the 확인 button.
Reference
  • Log storage settings can be changed when there is no log storage target.
  • To change the log storage bucket, first change the setting to inactive, then you can change it by setting it to active again.
How-to guides
Release Note