Skip to content

Firewall log

When troubleshooting problems with your firewall, it is very likely you have to check the logs available on your system. In the UI of Ixolate, the…

Updated View as Markdown

When troubleshooting problems with your firewall, it is very likely you have to check the logs available on your system. In the UI of Ixolate, the log files are generally grouped with the settings of the component they belong to. The log files can be found here:

Live View Firewall › Log Files › Live View *View firewall l ogs in realtime, smart filtering can be applied*
Plain View Firewall › Log Files › Plain View *Just the plain contents how* pf logs into filter.log

Live View

Live view updates itself in realtime if a rule is matched that has logging enabled or one of the global logging options is enabled under: System › Settings › Logging

In the top left corner of the page you can build filter conditions for rules to match when inspecting traffic, while here you can select different fields (for example label, src address, dst address) and how to match them (contains, is, is not, does not contain) combined with a criteria (either a string or a preselected value, depending on type). The [+] button adds the the filter to the view.

By default results should match all criteria (AND), but you can change that to an any of criteria (OR). The latter is sometimes practical if you want to track a small list of hosts.

Detailed information for a specific rule can be provided using the info button at the end of each line.

Overview

The logging overview page shows the distribution of the firewall log lines over a set of different properties, but is limited in the amount of rules it will evaluate (5000).

Although it may help to spot some clear patterns from the top of your log stash, the number of relevant use-cases is likely limited.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close