Ease of troubleshooting with Web Application Firewall logs
Enable Extend Logging option from NetScaler console. For more informaton on enabling the option, see View application security violation details.
Configuring verbose log level by using the command interface
set appfw profile <profile_name> -VerboseLogLevel (pattern|patternPayload|patternPayloadHeader)
Example
set appfw profile profile1 –VerboseLogLevel patternPayloadHeader
-
Pattern. Logs only violation pattern.
-
Pattern payload. Logs violation pattern and 150 bytes of extra field element payload.
-
Pattern payload header. Logs violation patter, 150 bytes of extra field element payload and HTTP header information.
Configuring verbose log level by using the NetScaler GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Profile Settings under Advanced Settings.
-
In the Profile Settings section, select the detailed WAF log level in the Verbose Log Level field.
-
Click OK and Done.Verbose log level configuration
Verbose logging for JSON security checks (SQL, CMD, and cross-site scripting)
-
SQL Injection
-
Cross-site scripting
-
Command Injection
Configure verbose logging for JSON security protection by using the CLI
set appfw profile <profile_name> -VerboseLogLevel ( pattern | patternPayload | patternPayloadHeader )
set appfw profile profile1 -VerboseLogLevel patternPayloadHeader
Configuring verbose log level by using the NetScaler GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, select JSON and click Action Settings.
-
In the JSON Security Settings page, set the Verbose log level parameter.
-
Click OK and Done.