juniper SRX650 设置IDP记录日志到文件设置match时的问题.md

juniper SRX650 设置IDP日志记录

http://junosnotes.blogspot.com/2012/08/srx-idp.html中说明


> help syslog | match IDP

IDP_APPDDOS_APP_ATTACK_EVENT_LS  IDP: DDOS attack on application

IDP_APPDDOS_APP_STATE_EVENT      IDP: DDOS application state transition event

IDP_APPDDOS_APP_STATE_EVENT_LS   IDP: DDOS application state transition event

IDP_ATTACK_LOG_EVENT_LS          IDP attack log

IDP_COMMIT_COMPLETED             IDP policy commit completed

IDP_COMMIT_FAILED                IDP commit exited with failure

IDP_DAEMON_INIT_FAILED           Failed to initialize IDP daemon

IDP_IGNORED_IPV6_ADDRESSES       IDP ingnores IPv6 addresses

IDP_INTERNAL_ERROR               IDP daemon encountered an internal error.

IDP_POLICY_COMPILATION_FAILED    IDP policy compilation failed

IDP_POLICY_LOAD_FAILED           Failed to load an IDP policy

在设置syslog是用的match 是 IDP_ATTACK_LOG_EVENT_LS,但一直没有日志记录,后改成RT_IDP

就有了,发现日志中记录的是这样的:



Oct 31 13:51:27   RT_IDP: IDP_ATTACK_LOG_EVENT: IDP: at 1477893086, SIG Attack log <180.173.206.150/19438->43.254.106.11/80> 

for TCP protocol and service SERVICE_IDP application NONE by rule 3 of rulebase IPS in policy Recommended. attack: repeat=0, action=DROP, 

threat-severity=HIGH, name=HTTP:APACHE:FILEUPLOAD-CNT-TYPE, NAT <0.0.0.0:0->172.16.50.2:0>, time-elapsed=0, inbytes=0, outbytes=0,

 inpackets=0, outpackets=0, intf:untrust:ge-0/0/0.0->trust:ae2.0, packet-log-id: 0, alert=no and misc-message -



原来并非 IDP_ATTACK_LOG_EVENT_LS, 而是IDP_ATTACK_LOG_EVENT

转载于:https://my.oschina.net/laofa1/blog/778534

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值