How to enable / access USG 110 detailed logs
We're using an USG 110 as main router and firewall. On the Traffic Statistics page, I can se one external IP address with Tx to of 65 GB. We would like to investigate more what kind of file transfer was done with this address. Where can we access those logs?
In the Log menu, we can only see 1024 log lines, and they are all from today.
Looking forward to hearing from you. Thank you!
0
Comments
-
Exactly, the log page only keep 1024. For this issue, we can monitor the session on "Monitor > System > Session Monitor". we can see the connection IP and service port.
If you would like to know the traffic content, we can investigate more information by packets capture. Go to "Maintenance > Diagnostics > Packets capture", set the fitter to capture packets for analysis.
eg. host ip = external IP address with Tx to of 65 GB .
0 -
Thank you Zyxel_Cooldia, appreciate!Just one question about the packets capture, it only captures the packets once launched. For example, if this Rx was one time, I cannot analyze the backlogs?0
-
It only can analysis current traffic by packets capture. we are unable to know the past traffic.
0 -
Roger that, thank you!
0 -
You can send traffic log to external syslog server for tracking.
The log information is like this,
src="192.168.111.37:52136" dst="178.32.169.230:80" msg="Traffic Log" note="Traffic Log" user="unknown" devID="cc5d4e5159cf" cat="Traffic Log" duration=5 sent=398 rcvd=1042 dir="lan1:wan1" protoID=6 proto="http" client_mac="00:30:18:C5:1C:6C"
You can got the sent/rcvd Bytes count of each session.
Be aware, enable traffic log might consume some CPU power depend on how many traffic volumes pass through your USG.
0 -
-
-> User accesses to Dropbox and Tx/Rx Bytes.
Thank you, but how to connect those two, by matching the log time?
0 -
-
Hi @Zyxel_Stanley , I do not understant your comment / the new topic you have added.Shall I follow up on this? What's the usage of creating the idea topic?As Zyxel USG is producing a lot of logs, I'm sure we can analyze those and get a detailed report. My question is: how to match accessed websites and traffic logs so that we can export statistics about:
User X accessed Y times the website Z and had a traffic of A Tx and B Rx.
0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight