Sophos Firewall Log Filter
Also if you perform a reload of the live log 20 30 lines of the log will load without filtering making it appear that nothing is being filtered.
Sophos firewall log filter. Is is not starts with and does not start with. If you want to filter on packet filter rule 25 use fwrule 25 as a filter. In this example clicking on web policy id 12 will redirect the administrator to the appropriate web policy edit page. If i click add filter and choose user name in the field box my only options for condition are.
All log files can be found in the webadmin at reports. In the console tree select a log. After that initial load it appears that the filter kicks in. In this example clicking on firewall rule id 2 will redirect the administrator to firewall rule id 2 s edit page.
Click add filter and select a field a condition and a value. Also when posting a line from the firewall log use the line from the full firewall log file. To filter the firewall log records. The info you see in the log log is formatted but the filter string operates on the raw data.
The reason the character doesn t work is that the character isn t used in the logs ar all. The cli can be accessed by going to admin console located in the upper right corner of the webadmin. You can also click on a field to add it as a filter. On the home page under firewall click view firewall log.
For information about the home page see about the home page. Find available values in the logfile guide. The sophos client firewall log viewer enables you to view filter and save details of the following. The default set of filters includes terms that are blocked by many organizations.
Unlike the other live logs the firewall live log omits the details needed to analyze a problem. Sophos xg firewall version 17 5 will allow administrators to jump from a specific log event to the appropriate intrusion prevention rule firewall rule or web filter policy. Filter the firewall log to show entries with no user name one of the columns in the firewall log is user name. You can use content filters in policies to restrict access to websites that contain any of the terms listed.
Connections that have been allowed or blocked. A content filter is a named list of terms. If you look in the actual firewall log file you will see that your filter term needs to be fwrule 1 instead of packet filter rule 1. The existing data will not be filtered.
Applies to the following sophos products and versions sophos firewall.