User`s manual
Traffic log message format
Traffic logs record each connection made to a DFL-500 interface. Each traffic log message records the date
and time at which the connection was made, the source and destination address of the connection, and
whether the connection was accepted or denied by the firewall.
Traffic log messages are created if you select one or more of the following log settings:
• Log All Internal Traffic to Firewall
• Log All External Traffic to Firewall
Traffic log messages are also created when a policy that is set to log traffic processes a connection.
A sample traffic log message contains the following information:
2002 Mar 25 09:50:47 TCP 192.168.1.23:60932=>192.168.1.99:47873 ACCEPT
Traffic log message format
describes the traffic log message format.
Traffic log message format
Description Format Example
Maximum
Length
Date and time the log message was
recorded
YYYY MMM DD
hh:mm:ss
2002 Mar 25
09:50:47
21 bytes
Protocol TCP , UDP , or ICMP
TCP
5 bytes
Source IP address and port number
ipaddress:port 192.168.1.23:60932
21 bytes
Destination IP and port
ipaddress:port 192.168.1.99:47873
21 bytes
TCP flag (optional) FIN or SYN 3 bytes
Action ACCEPT or DENY
ACCEPT
6 bytes
Event log message format
Event logs record changes made to the DFL-500 configuration using the web-based manager. Each event log
message records the date and time at which the change was made, a description of the change, and the IP
address of the management computer from which the change was made.
Event log messages are created if you select the Log All Event setting.
A sample Event log message contains the following information:
2002 Mar 25 09:50:56 Log-Event elong delete successful at 192.168.1.23 by admin
Event log message format
describes the event log message format.
Event log message format
Description Format Example
Maximum
Length
Date and time the log message was
recorded
YYYY MMM DD
hh:mm:ss
2002 Mar 25 09:50:56
21 bytes
Event description
description
Log-Event elog
delete
21 bytes
Result successful or failed
successful
10 bytes
IP address from which the event was
received
at ipaddress at 192.168.1.23
20 bytes
Administrative user that caused the event by adminuser by admin 20 bytes
DFL-500 User’s Manual
86