This article provides information about configuring traffic (security policy) logs for SRX High-End Devices: SRX1400, SRX3400, SRX3600, SRX4100, SRX4200, SRX4600, SRX5600, and SRX5800. For information about configuring system logs or traffic logs for SRX Branch devices, refer to KB16634 - SRX Getting Started - Configure Logging [juniper.net] . For other topics, go to the SRX Getting Started main page.
Configure logging so that security log messages are sent directly from traffic interface ports to a remote syslog server.
This section contains the following:
eventd
fxp0
To send traffic (security policy) logs to a remote syslog server, you must configure the following:
user@host#
set security log source-address 10.30.30.1
set security log stream trafficlogs host 192.30.80.76
default-permit
session-close
session-init
user@host# set security policies from-zone trust to-zone untrust policy default-permit then log session-close
set security policies from-zone trust to-zone untrust policy default-permit then log session-init
To verify that traffic logs are being sent to the syslog server, check the remote syslog server.
2020-06-30: Added SRX4100, SRX200, SRX4600 to the summary.