Starting with Junos OS Release 15.1X49-D100, J-Web supports on-box reporting on the SRX. This article shows how to configure and use on-box reporting in J-Web.
Notes:
Below are the Techlibrary links for the each function. Please refer to them for more information.
mode (Security Log) Understanding On-Box Logging and Reporting
On the Security Logging screen, do the following:
Select Stream Mode for the Logging Type.
Click Enable Traffic Logs to enable security logging. If there is no Syslog server in your environment, you can still use on-box reporting without any Syslog server settings. If you have a Syslog server, add the Syslog sever. Click Apply .
If there is no Syslog server setting, the following message will be reported for the notification. If it is OK to proceed, click Yes button and commit the configuration.
The CLI commands to enable the on-box reporting feature are:
set security log mode stream set security log report
Once the commit is done, select Monitor > Events > All Events.
A summary of all events will be displayed.
Clicking the "Attacks" link (highlighted in the red box above) displays the detail of the attacks:
In the Events hierarchy, the individual functions can be selected for more details:
Since the supported logging mode was changed from event mode to stream mode, J-Web will not display event mode logs, such as the messages log in the event monitor on 15.1X49-D100 and later. If it is necessary to get the event mode log through J-Web, do the following steps:
1. Select Administration > Devices > Files. and click Log Files .
2. Find a log file which you want to see from the list, and click Download to get the file.
2020-03-27: Article reviewed for accuracy; no changes required.