TMS zl Management and Configuration Guide ST.1.1.100430

3-48
Initial Setup in Monitor Mode
Configuring Event Logging
Configuring Event Logging
The TMS zl Module logs events sent from the following sources:
Security systems (IDS)
Open architecture system
Startup scripts (initialization and reboot)
Management systems (Web browser, CLI, and SNMP)
Common services (TFTP, SCP, and others)
There are four mechanisms for logging events that the TMS zl Module detects:
Local logging—The module keeps its own internal logs, which may be
exported to a compressed .tar file (.tgz extension). (See “View and Export
Local Logs” on page 3-52.)
Email forwarding—The module can send alerts to as many as three
email accounts. (See “Configure Email Forwarding” on page 3-53.)
Syslog forwarding—The module can forward log entries to up to three
syslog servers. (See “Configure Syslog Forwarding” on page 3-54.)
SNMP traps—The module can forward SNMP traps to one or more SNMP
servers. (See “Configure SNMP Traps” on page 3-55.)
Log Settings
The TMS zl Module allows you to control:
Log severity—the type of messages that are logged for TMS zl Module
events
Log threshold monitor—a safeguard that prevents excessive logging
from negatively impacting the module’s performance
Log throttling—the number of duplicate messages that are logged for
the same event