The page has been translated by Gen AI.

Firewall Logging

To store Firewall logs, you must first create a bucket in Object Storage to store the logs, set the bucket as the log storage in Firewall Logging, and then set log storage on the Firewall Details page to store Firewall logs in the Object Storage bucket.

To store Firewall logs, set up according to the following order:

  1. To store firewall logs, you can create a bucket in Object Storage or use an already created bucket. To create a bucket, refer to Creating Object Storage.
  2. To set the bucket as the log storage in Firewall Logging, refer to Using Firewall Logging Log Storage.
  3. To set log storage status to Use in Firewall details, refer to Using Firewall Log Storage.

Setting Up Firewall Logging Log Storage

To set the Firewall log storage status to Use, you must first set the log storage in Firewall Logging.

Note
To set Firewall Logging log storage, you need an Object Storage bucket for log storage. First, create a bucket in the Object Storage service. For more information, refer to Creating Object Storage.

To set up Firewall Logging log storage, follow these steps:

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. You will be redirected to the Firewall Logging List page.
  2. On the Firewall Logging List page, click the Log Storage Settings button at the top. You will be redirected to the Log Storage Settings popup window.
  3. In the Log Storage Settings popup window, select the Log Storage Bucket. When you select a bucket, the Log Storage Path is displayed.
  4. In the Log Storage Settings popup window, check the Log Storage Bucket and Log Storage Path, and then click the Confirm button.
  5. Check the message in the Notification popup window and click the Confirm button.
Notice
After setting up the Firewall Logging log storage, you must set log storage status to Use on the Firewall Details page to start log storage. For more information, refer to Using Firewall Log Storage.

Viewing Firewall Logging List

When you set the Firewall Logging log storage bucket, you can view the Firewall Logging list.

To view the Firewall Logging list, follow these steps:

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. You will be redirected to the Firewall Logging List page.
  2. On the Firewall Logging List page, check the resources in use and log storage targets.
    DivisionDescription
    Resource IDFirewall ID
    Storage TargetFirewall name
    Storage Registration DateFirewall log storage registration date
    Table. Firewall Logging list items
Note
After setting up the Firewall Logging log storage, you must set log storage status to Use in Firewall details to start log storage. For more information, refer to Using Firewall Log Storage.

Checking Firewall Logging Detailed Content

Refer to the following content to check the detailed content of stored logs.

Stored log example: 2024-10-11T11:23:43,deny,0,17,4.1.1.100,45499,192.168.10.10,53

DivisionDescription
2024-10-11T11:23:43Date and time when the log occurred (2024-10-11, 11:23:43)
denyAction (deny / accept)
0Firewall Rule ID (Policy ID) where the log occurred
17IP Protocol ID
  • 1: ICMP
  • 6: TCP
  • 17: UDP
4.1.1.100Source IP
45499Source Port
192.168.10.10Destination IP
53Destination Port
Table. Log detailed information items

Setting Firewall Logging Log Storage to Not Use

You can set the log storage in Firewall Logging to not use.

To set Firewall Logging log storage to not use, follow these steps:

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. You will be redirected to the Firewall Logging List page.
  2. On the Firewall Logging List page, click the Log Storage Settings button at the top. You will be redirected to the Log Storage Settings popup window.
  3. In the Log Storage Settings popup window, select Not Use for the Log Storage Bucket and click the Confirm button.
Note
  • Log storage settings can be changed when there is no log storage target.
  • To change the log storage bucket, first change the setting to not use. Then you can change it by setting it to use again.
How-to guides
Release Note