Set Logging and Notification Preferences

The logging and notification preferences are similar throughout the Firebox configuration. Logging and notification preferences control when and what types of log message the Firebox generates when an event occurs.

You can configure logging and notification settings in many locations in the Firebox configuration. For example:

  • Firewall policies and proxies — Alarm notification for policy and proxy events
  • Firebox feature key — Alarm notification when a feature key is expired or expires soon
  • Default Packet Handling — Logging and alarm notification for specific types of attacks and events
  • Blocked Sites and Blocked Ports — Logging and alarm notification for blocked site and blocked port events
  • Intrusion Prevention — Alarm notification when IPS generates an alarm
  • BOVPN — Alarm notification for BOVPN events
  • Multi-WAN — Alarm notification for multi-WAN events
  • FireCluster — Alarm notification for FireCluster events

Most of the options described in this topic are available in each location where you can define logging and notification preferences.

Logging and Notification Settings

The logging and notification settings you can configure are:

Logging and Notification in Policies

Where you configure policy logging settings depends on the type of policy. The setting that controls logging for reports is different for packet filter policies and proxy policies.

Packet filter policies

For packet filter policies, you configure these logging settings in the policy properties:

  • Send Log Message
  • Send a Log Message for Reports
  • Send SNMP Trap
  • Send Email Notification (Fireware v12.11 and higher) or Send Notification (Fireware v12.10.4 and lower)

The Send a Log Message for Reports setting appears only in packet filter policies that allow connections. Packet filter policies that deny connections always generate log messages for reports.

Screen shot of the logging and notification settings for a packet filter policy that allows connections

Logging settings for a packet filter policy that allows connections, in Fireware Web UI

Fireboxes that run Fireware v12.10.3 or higher include additional information in some types of log messages when you select the Send a Log Message for Reports setting. For more information, go to Read a Log Message.

The Pop-Up Window option in Fireware v12.10.4 and lower does not generate a pop-up notification. To generate an alert in WatchGuard Cloud, select the Email notification method. For more information, go to Configure Firebox Notification Rules.

Proxy policies

For proxy policies, you configure these logging settings in the policy properties.

  • Send Log Message
  • Send SNMP Trap
  • Send Email Notification (Fireware v12.11 and higher) or Send Notification (Fireware v12.10.4 and lower)

For proxy policies, the setting that enables the Firebox to send a log message for reports is in the proxy action, and is called Enable Logging for Reports.

Screen shot of the logging settings in a proxy action in Fireware Web UI

Logging settings for a proxy action in Fireware Web UI.

Proxy actions also include a setting to override the diagnostic log level for policies that use the proxy action. For information about the diagnostic log levels, go to Set the Diagnostic Log Level.

Related Topics

About Firebox Logging and Notification

About SNMP Traps for Alarms

About Notification