How to Set Up Log Alerts for IP Reputation?

Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,511  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
edited August 9 in Maintenance

Question: 

How can I receive alerts for IP reputation logs via email?

Answer: 

To receive email alerts only when there is a blocked IP reputation event, you will need to use an external syslog server. Here are the steps to set this up:

  1. Set the firewall to send event logs to an external syslog server:
    • Access the firewall's configuration settings.
    • Navigate to the logging options and select to forward logs to an external syslog server.
    • Input the IP address and port number of your syslog server.
  2. Configure your external syslog server:
    • Install the syslog software on your server.
    • Set up filters to parse and filter log messages based on keywords. For IP reputation, filter logs where action is 'blocked'.
    • Enable email alerts for the filtered events, specifying the recipient email address.