Configuring NetScaler appliance for audit logging
Configuring audit log policies in a classic policy expression
-
Configuring an audit log action. You can configure an audit action for different servers and for different log levels. 'Audit action' describes Audit Server configuration information whereas 'audit policy' links a bind entity to an 'audit action'. By default, the SYSLOG uses a user data protocol (UDP) for data transfer and NSLOG uses only TCP to transfer log information to the log servers. TCP is more reliable than UDP for transferring complete data. When using TCP for SYSLOG, you can set the buffer limit on the NetScaler appliance to store the logs. After the buffer limit is reached, the logs are sent to the SYSLOG server.
-
Configuring audit log policy. You can configure either SYSLOG policies to log messages to a SYSLOG server or NSLOG policy to log messages to an NSLOG server. Each policy includes a rule that is set to
trueorns_truefor the messages to be logged, and a SYSLOG or NSLOG action. -
Binding audit log policies to global entities. You must globally bind the audit log policies to global entities such SYSTEM, VPN, NetScaler AAA and so on. You can do it to enable logging of all NetScaler system events. By defining the priority level, you can set the evaluation order of the audit server logging. Priority 0 is the highest and is evaluated first. The higher the priority number, the lower is the priority of evaluation.
Configuring audit log action
- add audit syslogAction <name> <serverIP> [-serverPort <port>] -logLevel <logLevel> [-dateFormat ( MMDDYYYY | DDMMYYYY )] [-transport ( TCP | UDP )]`
- show audit syslogAction [<name>]
- add audit nslogAction <name> <serverIP> [-serverPort <port>] -logLevel <logLevel> [-dateFormat ( MMDDYYYY | DDMMYYYY )]
- show audit nslogAction [<name>]
Configuring audit log policies
- add audit syslogpolicy <name> <-rule> <action>
- add audit nslogpolicy <name> <-rule> <action>
Binding audit syslog policies to audit syslog global
bind syslogGlobal -policyName <policyName> -priority <priority>
unbind syslogGlobal -policyName <policyName> -priority <priority>
bind systemglobal <policy Name> <Priority>
unbind systemglobal <policy Name> <Priority>
Configuring audit log policies using advanced policy expression
-
Configuring an audit log action. You can configure an audit action for different servers and for different log levels. 'Audit action' describes Audit Server configuration information whereas 'audit policy' links a bind entity to an 'audit action'. By default, SYSLOG uses a user data protocol (UDP) for data transfer and NSLOG uses only TCP to transfer log information to the log servers. TCP is more reliable than UDP for transferring complete data. When using TCP for SYSLOG, you can set the buffer limit on the NetScaler appliance to store the logs. After the buffer limit is reached, the logs are sent to the SYSLOG server.
-
Configuring audit log policy. You can configure either SYSLOG policies to log messages to a SYSLOG server or NSLOG policy to log messages to an NSLOG server. Each policy includes a rule that is set to
trueorns_truefor the messages to be logged, and a SYSLOG or NSLOG action. -
Binding audit log policies to global entities. You must globally bind the audit log policies to SYSTEM global entity to enable logging of all NetScaler system events. By defining the priority level, you can set the evaluation order of the audit server logging. Priority 0 is the highest and is evaluated first. The higher the priority number, the lower is the priority of evaluation.
Configuring audit log action
- add audit syslogAction <name> <serverIP> [-serverPort <port>] -logLevel <logLevel> [-dateFormat ( MMDDYYYY | DDMMYYYY )] [-transport ( TCP | UDP )]
- show audit syslogAction [<name>]
- add audit nslogAction <name> <serverIP> [-serverPort <port>] -logLevel <logLevel> [-dateFormat ( MMDDYYYY | DDMMYYYY )]
- show audit nslogAction [<name>]
Configuring audit log policies
-managementlog and -mgmtloglevel parameters are only available in NetScaler 13.1-37.199 and later FIPS releases.
add audit syslogAction <name> (<serverIP> | ((<serverDomainName>[-domainResolveRetry <integer>])
| -lbVserverName <string>))[-serverPort <port>] -logLevel <logLevel> [-managementlog <managementlog> ...] ... [-mgmtloglevel <managementloglevel> ...][-dateFormat <dateFormat>]
[-logFacility <logFacility>][-tcp ( NONE | ALL )] [-acl ( ENABLED | DISABLED )]
[-timeZone ( GMT_TIME | LOCAL_TIME )][-userDefinedAuditlog ( YES | NO )]
[-appflowExport ( ENABLED | DISABLED )] [-lsn ( ENABLED | DISABLED )][-alg ( ENABLED | DISABLED )]
[-subscriberLog ( ENABLED | DISABLED )][-transport ( TCP | UDP )] [-tcpProfileName <string>][-maxLogDataSizeToHold]
> add audit syslogaction audit-action1 10.102.1.1 -loglevel INFORMATIONAL -dateformat MMDDYYYY
> add audit nslogAction nslog-action1 10.102.1.3 -serverport 520 -loglevel INFORMATIONAL -dateFormat MMDDYYYY
> add audit syslogpolicy syslog-pol1 TRUE audit-action1
> add audit nslogPolicy nslog-pol1 TRUE nslog-action1
> bind system global nslog-pol1 -priority 20
add audit nslogAction <name> (<serverIP> | (<serverDomainName>[-domainResolveRetry <integer>])) [-serverPort <port>] -logLevel <logLevel> ... [-dateFormat <dateFormat>][-logFacility <logFacility>] [-tcp ( NONE | ALL )][-acl ( ENABLED | DISABLED )] [-timeZone ( GMT_TIME | LOCAL_TIME )][-userDefinedAuditlog ( YES | NO )][-appflowExport ( ENABLED | DISABLED )] [-lsn ( ENABLED | DISABLED )][-alg ( ENABLED | DISABLED )] [-subscriberLog ( ENABLED | DISABLED )]`
Binding audit log policies to global entities
bind audit syslogGlobal <policyName> [-globalBindType <globalBindType
unbind audit syslogGlobal <policyName>[-globalBindType <globalBindType>]
Configuring audit log policy by using the GUI
-
Navigate to Configuration > System > Auditing > Syslog.
-
Select Servers tab.
-
Click Add.
-
In the Create Auditing Server page, populate the relevant fields, and click Create.
-
To add the policy, select the Policies tab, and click Add.
-
In the Create Auditing Syslog Policy page, populate the relevant fields, and click Create.
-
To bind the policy globally, select Advanced Policy Global Bindings from the drop-down list. Select the best_syslog_policy_ever policy. Click Select.
-
From the drop-down list, select the bind point as SYSTEM_GLOBAL and click Bind, and then click Done.
Configuring policy-based logging
Prerequisites
-
User Configurable Log Messages (userDefinedAuditlog) option is enabled for when configuring the audit action server to which you want to send the logs in a defined format.
-
The related audit policy is bound to system global.
Configuring an audit message action
Create an audit message action by using the CLI
add audit messageaction <name> <logLevel> <stringBuilderExpr> [-logtoNewnslog (YES|NO)]add audit messageaction log-act1 CRITICAL '"Client:"+CLIENT.IP.SRC+" accessed "+HTTP.REQ.URL'