Re: [j-nsp] how to send SRX240 traffic/session logs to syslog server

2017-06-22 Thread Aaron Gould
Oh my gosh, guess what….Syslog traps were arriving at the server all along….but were going into /var/log/daemon.log …and I was grepping on /var/log/syslog :| Thanks for all your suggestions… At this point using just 2 statements for “set system syslog host …. source-address …”… I see

Re: [j-nsp] how to send SRX240 traffic/session logs to syslog server

2017-06-19 Thread Jed Laundry
Hi Aaron, Have you enabled logging on each policy you're interested in? I.e.: then { permit; log { session-init; session-close; } Thanks, Jed. -- On Tue, 20 Jun 2017 at 09:29, Aaron Gould wrote: > Thanks Mike, Per the web link I tried the following but still don’

Re: [j-nsp] how to send SRX240 traffic/session logs to syslog server

2017-06-19 Thread Aaron Gould
Thanks Mike, Per the web link I tried the following but still don’t see session/flow logs from the SRX… set security log stream log3 format welf category content-security host 10.51.16.9 set security log source-address 1.2.3.4 -Aaron ___ jun

Re: [j-nsp] how to send SRX240 traffic/session logs to syslog server

2017-06-19 Thread Michael Gehrmann
I suggest stream logging: https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/security-system-stream-security-log-revenue-port-setting.html We use this on every SRX we have for traffic logging. Regards Mike > On 19 Jun 2017, at 21:45, Aaron Gould wrote: > > I'm trying

[j-nsp] how to send SRX240 traffic/session logs to syslog server

2017-06-19 Thread Aaron Gould
I'm trying to send SRX240 traffic/session logs to a syslog server... i have some system messages going to the syslog server, but not the session/traffic logs. What do i need to do ? i'll show you some info from the syslog stanzalet me know if you need to see anything else... {prima