The page has been translated by Gen AI.

Firewall Logging

To store firewall logs, first create a bucket in Object Storage for the logs and configure that bucket in the log repository of Firewall Logging. Then, on the Firewall Details page, set up log storage, and the firewall logs will be saved to the Object Storage bucket.

To save firewall logs, configure it according to the following steps.

  1. To store firewall logs, you can create a bucket in Object Storage or use an existing bucket. To create a bucket, refer to Create Object Storage.
  2. To set the bucket for the Firewall Logging log repository, refer to Firewall Logging 로그 저장소 사용하기.
  3. To set the log storage option to Enabled in the detailed view of the Firewall, refer to Using Firewall Log Storage.

Firewall Logging Configure log storage usage

To set the firewall’s log storage to enabled, you must first configure the log repository in Firewall Logging.

Reference
Firewall Logging To set up a log repository, you need an Object Storage bucket for log storage. First, create a bucket in the Object Storage service. For more details, please refer to Create Object Storage.

To enable the Firewall Logging log repository, follow these steps.

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. Go to the Firewall Logging List page.
  2. On the Firewall Logging List page, click the top Log Storage Settings button. You will be taken to the Log Storage Settings popup.
  3. Log storage settings In the popup window, select the log storage bucket. When you select a bucket, the log storage path is displayed.
  4. Log storage settings In the popup window, after verifying Log storage bucket and Log storage path, click the Confirm button.
  5. Notification After reviewing the popup message, click the Confirm button.
guide
After setting the log repository, on the Firewall Details page, you must set the log saving option to Enabled for logging to start. For more details, refer to Using Firewall Log Storage.

View Firewall Logging List

If you configure the Firewall Logging log storage bucket, you can view the Firewall Logging list.

To view the Firewall Logging list, follow these steps.

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. You will be taken to the Firewall Logging List page.
  2. On the Firewall Logging List page, verify the resources in use and the log storage targets.
    CategoryDetailed description
    Resource IDFirewall ID
    Save targetFirewall name
    Save registration date and timeFirewall log repository registration timestamp
    Table. Firewall Logging list items
Reference
After setting the log repository for Firewall Logging, you must set the log storage option to Enabled in the Firewall detail view for logging to start. For more details, please refer to Using Firewall Log Storage.

Check detailed information of Firewall Logging

Refer to the information below to view the detailed contents of the stored log.

Stored log example: 2024-10-11T11:23:43,deny,0,17,4.1.1.100,45499,192.168.10.10,53

Categorydescription
2024-10-11T11:23:43Date and time of the log occurrence (2024-10-11, 11:23:43)
denyAction (deny / accept)
0Firewall Rule ID (Policy ID) that generated the log
17IP Protocol ID
  • 1: ICMP
  • 6: TCP
  • 17: UDP
4.1.1.100Source IP
45499Departure Port
192.168.10.10Destination IP
53Destination Port
Table. Log detailed information items

Firewall Logging Configure to not use log storage

In Firewall Logging, you can set the log repository to unused.

Firewall Logging To disable the log repository, follow the steps below.

  1. Click the All Services > Management > Network Logging > Firewall Logging menu. You will be taken to the Firewall Logging List page.
  2. Firewall Logging List page, click the top Log Storage Settings button. You will be taken to the Log Storage Settings popup.
  3. Log storage settings In the popup window, select Log storage bucket as Not used, and click the Confirm button.
Reference
  • Log storage settings can be changed when no log storage target is configured.
  • To change the log storage bucket, first set it to disabled. Then you can modify it by re-enabling it.
How-to guides
Migration Rules