Audit logging
Local logging
ns.log file under the /var/log/ folder. Since local logging is enabled by default, you don't need to perform any additional configurations to store the logs.
-
Accessibility: You can access the logs even if there are network issues. The logs can be accessed quickly because they are not dependent on network connections.
-
Security: The sensitive or confidential data remains within NetScaler and therefore reduces the risk of unauthorised access.
-
Compliance: Many regulatory requirements mandate the retention of log data for a certain period. So, by storing logs locally NetScaler ensures that it is compliant.
Log levels
-
ALERT - Requires immediate action to prevent further issues. These are high-priority messages.
-
CRITICAL - Indicates a critical condition that might affect the system's functionality.
-
EMERGENCY - Indicates a critical system failure that requires immediate attention. The system is likely unusable.
-
ERROR - Logs errors that have occurred but do not necessarily require immediate action.
-
INFORMATIONAL - The informational logs provide general information about NetScaler.
-
NOTICE - Provides informational messages about normal but significant events.
-
WARNING - Indicates potential issues or situations that could lead to problems if not addressed.
-
DEBUG - The debug logs provide detailed information for troubleshooting.
-
ALL - Includes all log levels except DEBUG.
-
NONE - Does not contain any log details.
set syslogparams -loglevel -debug.
set syslogparams -acl ( ENABLED | DISABLED )
-alg ( ENABLED | DISABLED )
-appflowExport ( ENABLED | DISABLED )
-ContentInspectionLog ( ENABLED | DISABLED )
-dateFormat <dateFormat>
-dns ( ENABLED | DISABLED )
-logFacility <logFacility>
-logLevel <logLevel> ...
-lsn ( ENABLED | DISABLED )
-serverIP <ip_addr|ipv6_addr|*>
-serverPort <port>
-sslInterception ( ENABLED | DISABLED )
-subscriberLog ( ENABLED | DISABLED )
-tcp ( NONE | ALL )
-timeZone ( GMT_TIME | LOCAL_TIME )
-urlFiltering ( ENABLED | DISABLED )
-userDefinedAuditlog ( YES | NO )
-
Performance impact - Logging activities can consume system resources that can potentially impact the performance and stability of NetScaler.
-
Storage: NetScaler can store only a limited amount of log data since the local storage capacity is low compared to centralized storage.
-
Scalability - Not suitable for large-scale deployments. In large-scale deployments, centralized logging solutions are preferred for easier management and scalability.
-
Compliance challenges in large scale deployments - Many industries have regulations and compliance requirements regarding log management and retention. Managing compliance becomes more complex when logs are stored locally, as it requires ensuring that each device adheres to the necessary standards.
-
-
Accessibility in large scale network - Accessing logs stored locally on NetScaler might require direct access to the device. This becomes inconvenient in large networks because accessing logs from multiple devices that are distributed across a network is cumbersome.
-
Single point of failure - If there is a hardware malfunction, any logs stored locally becomes inaccessible. This creates a single point of failure for logging data, potentially leading to loss of valuable information.
Remote logging
SYSLOG and NSLOG
-
SYSLOG auditing module: Runs on NetScaler.
-
SYSLOG server: Runs on the underlying FreeBSD operating system (OS) of NetScaler or on a remote system.
-
NSLOG auditing module: Runs on NetScaler.
-
NSLOG server: Runs on the underlying FreeBSD OS of NetScaler or on a remote system.
-
The IP address of NetScaler that generated the log message.
-
A time stamp
-
The message type
-
The predefined log levels (Critical, Error, Notice, Warning, Informational, Debug, Alert, and Emergency)
-
The message information
healthMonitor parameter in the set service command to NO. For configuring ICMP, see Load balancing SYSLOG messages across external log servers