Add > Filter > Filter Builder | Use Filter Builder to
create new log filters. Select Create Filter to construct
filters and, for each query in a new filter, specify the following settings
and then Add the query: Connector—Select
the connector logic (and or or).
Select Negate if you want to apply negation.
For example, to avoid forwarding a subset of log descriptions, select Description as
the Attribute, select contains as the Operator,
and enter the description string as the Value to identify the description
or descriptions that you don’t want to forward. Attribute—Select a log attribute.
The options vary by log type. Operator—Select the criterion that
determines how the attribute applies (such as contains).
The options vary by log type. Value—Specify the attribute value
to match. Add—Add the new filter.
To
display or export logs that the filter matches, select View
Filtered Logs. To find matching log entries,
you can add artifacts to the search field, such as an IP address
or a time range. Select the time period for which you want to see logs: Last
15 Minutes, Last Hour, Last
6 Hrs, Last 12 Hrs, Last
24 Hrs, Last 7 Days, Last
30 Days, or All (default). Use the options to the right of the time period drop-down
to apply, clear, add, save, and load filters: Apply
filters (
)—Display
log entries that match the terms in the search field. Clear filters (
)—Clear
the filter field. Add a new filter (
)—Define
new search criteria (takes you to Add Log Filter, which is similar
to create filters). Save a filter (
)—Enter
a name for the filter and then click OK. Use a saved filter (
)—Add
a saved filter to the filter field. Export to CSV (
)—Export
logs to a CSV-formatted report and then Download file.
By default, the report contains up to 2,000 lines of logs. To change
the line limit for generated CSV reports, select and enter a new Max
Rows in CSV Export value.
You
can change the number and order of entries displayed per page and you
can use the paging controls at the bottom left of the page to navigate
through the log list. Log entries are retrieved in blocks of 10 pages. per page—Use the drop-down to change the number of
log entries per page (20, 30, 40, 50, 75,
or 100). ASC or DESC—Select ASC to
sort results in ascending order (oldest log entry first) or DESC to
sort in descending order (newest log entry first). The default is DESC. Resolve Hostname—Select to resolve
external IP addresses to domain names. Highlight Policy Actions—Specify an
action and select to highlight log entries that match the action.
The filtered logs are highlighted in the following colors: Green—Allow Yellow—Continue or override Red—Deny, drop, drop-icmp, rst-client, reset-server, reset-both, block-continue,
block-override, block-url, drop-all, sinkhole
|