Auditing policies
To create an auditing server by using the command line interface
-
add audit syslogAction <name> <serverIP> [-serverPort <port>] -logLevel <logLevel> ... [-dateFormat ( MMDDYYYY | DDMMYYYY )] [-logFacility <logFacility>] [-tcp ( NONE | ALL )] [-acl ( ENABLED | DISABLED )] [-timeZone ( GMT_TIME | LOCAL_TIME )] [-userDefinedAuditlog ( YES | NO )] [-appflowExport ( ENABLED | DISABLED )] -
save ns config
Example
add audit syslogAction syslog1 10.124.67.91 -logLevel emergency critical warning -logFacility
LOCAL1 -tcp ALL
save ns config
To modify or remove an auditing server by using the command line interface
-
To modify an auditing server, type the set audit
<type>command, the name of the auditing server, and the parameters to be changed, with their new values. -
To remove an auditing server, type the rm audit
<type>command and the name of the auditing server.
Example
set audit syslogAction syslog1 10.124.67.91 -logLevel emergency critical warning alert error
-logFacility LOCAL1 -tcp ALL
save ns config
To create or configure an auditing server by using the GUI
-
Navigate to Security > NetScaler Web App Firewall > Policies > Auditing > Nslog.
-
In the Nslog Auditing page, click Servers tab.
-
Do one of the following:
-
To add a new auditing server, click Add.
-
To modify an existing auditing server, select the server, and then click Edit.
-
-
In the Create Auditing Server page, set the following parameters:
-
Name
-
Server Type
-
IP Address
-
Port
-
Log Levels
-
Log Facility
-
Date Format
-
Time Zone
-
TCP Logging
-
ACL Logging
-
User Configurable Log Messages
-
AppFlow® Logging
-
Large Scale NAT Logging
-
ALG messages logging
-
Subscriber logging
-
SSL Interception
-
URL Filtering
-
Content Inspection Logging
-
-
Click Create and Close.
To create an auditing policy by using the command line interface
-
add audit syslogPolicy <name> <-rule > <action> -
save ns config
Example
add audit syslogPolicy syslogP1 rule "ns_true" action syslog1 save ns config
To configure an auditing policy by using the command line interface
-
set audit syslogPolicy <name> [-rule <expression>] [-action <string>] -
save ns config
Example
set audit syslogPolicy syslogP1 rule "ns_true" action syslog2 save ns config
To configure an auditing policy by using the GUI
-
Navigate to Security > NetScaler Web App Firewall > Policies.
-
In the details pane, click Audit Nslog Policy.
-
In the Nslog Auditing page, click Policies tab and do one of the following:
-
To add a new policy, click Add.
-
To modify an existing policy, select the policy, and then click Edit.
-
-
In the Create Auditing Nslog Policy page, set the following parameters:
-
Name
-
Auditing Type
-
Expression Type
-
Server
-
-
Click Create.