TMS zl Management and Configuration Guide ST.1.2.100916
3-51
Initial Setup in Monitor Mode
Configuring Event Logging
Configuring Event Logging
The TMS zl Module logs events sent from the following sources:
■ Security systems (IDS)
■ Open architecture system
■ Startup scripts (initialization and reboot)
■ Management systems (Web browser, CLI, and SNMP)
■ Common services (TFTP, SCP, and others)
There are four mechanisms for logging events that the TMS zl Module detects:
■ Local logging—The module keeps its own internal logs, which may be
exported to a compressed .tar file (.tgz extension). (See “View and Export
Local Logs” on page 3-55.)
■ Email forwarding—The module can send alerts to as many as three
email accounts. (See “Configure Email Forwarding” on page 3-56.)
■ Syslog forwarding—The module can forward log entries to up to three
syslog servers. (See “Configure Syslog Forwarding” on page 3-57.)
■ SNMP traps—The module can forward SNMP traps to one or more SNMP
servers. (See “Configure SNMP Traps” on page 3-58.)
Log Settings
The TMS zl Module allows you to control:
■ Log severity—the type of messages that are logged for TMS zl Module
events
■ Log threshold monitor—a safeguard that prevents excessive logging
from negatively impacting the module’s performance
■ Log throttling—the number of duplicate messages that are logged for
the same event