Description

What Is the Trap Log Format When Exporting Logs to SNMP Manager?

Symptoms


Solution

When the log action is configured to forward logs from NetScreen-Security Manager (NSM) to the SNMP Manager as a trap, the complete log entry is forwarded to the SNMP Manager using the OID value enterprises.2326.1.1.1.0 .

The following is the SNMP trap log format:

Image of example.

day id : Date on which the log was generated
record id : ID of the log provided by NSM
Time Generated in GMT : Time when the log was generated, converted to GMT
Local Time for Log Received : Time when the log was received (local time from the NSM UI)
Domain : Domain where the device was configured
Device Domain Version : Version of the domain that created the log
Device : Name of the host that created the log
Category : Category of the log
Sub-Category : Sub-category of the log
Source Zone : Source zone of the traffic
Source Interface : (No current details)
Source Address : Source address of the traffic
Source Port : Source port used for the traffic
NAT Source Address : Translated source address
NAT Source Port : Translated source port
Destination Zone : Destination zone of the traffic
Destination Interface : (No current details)
Destination Address : Destination IP address of the traffic
Destination Port : Destination port used for the traffic
NAT Destination Address : Translated destination address
NAT Destination Port : Translated destination port
Protocol : Protocol used for the traffic
Rule Domain : Domain in which the rule is present
Rule Domain Version : Version of the domain for the rule
Policy Name : Name of the policy that generated the log
Rulebase : Specifies whether the rulebase was the VPN policy or the security policy
Rule Number : Specifies the rule number
Action : Action taken on the traffic
Severity : Severity of the traffic
Alert : Displays type of alert
Misc String : Miscellaneous string flag
User Flag : Any user flags defined
App String : Details on the log
URI String : Internal value of URI string
Elapsed Seconds : Time in seconds for the traffic
Bytes In : Number of bytes in
Bytes Out : Number of bytes out
Bytes Total : Total number of bytes
Packets In : Number of packets in
Packets Out : Number of packets out
Total Packets : Total number of packets
Repeat Count : Number of times the logs are repeated
Packet Data : Dispalys log packet data
Enum Value : Indicates data type, such as FTP or SIP



Former Article Id

ns10782