Configure protocols for advanced logging

Advanced logging for application protocols allows you to monitor and analyze network connections by capturing detailed information about specific application protocols. This feature is configured at the access control policy level and can be applied to individual rules within the policy.

Before you begin

Ensure that you have enabled the advanced logging feature for the access control policy that you want to modify.

Follow these steps to configure protocols for advanced logging:

Procedure


Step 1

Choose Policies > Security policies > Access Control.

Step 2

Click Edit (edit icon) next to the access control policy you want to edit.

If View (View button) appears instead, the configuration belongs to an ancestor domain, or you do not have permission to modify the configuration.

Step 3

In the access control policy editor, you have the options to add a new rule or edit an existing rule.

  • To add a new rule, click Add Rule.

  • To edit an existing rule, click Edit (edit icon).

Step 4

Click Advanced Logging.

Step 5

Check the check box next to the application protocol for which you want to log the connection.

Caution

Enabling logging for all the protocols in a Firewall Threat Defense device might affect its performance, because the device must extract data, convert it to targeted formatting, and send it to the configured destination.

Step 6

Click Confirm.

Step 7

Click Apply to save the rule.

Step 8

Click Save to save the policy.


What to do next

Deploy configuration changes.