SunScreen 3.2 Administration Guide

Setting a Log Viewing Filter

The Log Browser filters log events to be displayed. The language that it uses is identical to the filtering options of the logdump command in the command-line program; it is a superset of the language used by the Solaris snoop packet monitor tool.

You have full access to this language typing an arbitrary logdump expression in the Current Filter text entry box in its Retrieval Settings tab and clicking the Apply button to activate it.

In addition, the Filter Keywords controls provide the ability to create many simple filtering expressions. These controls reduce typing effort as well as serving as reminders of filtering options.

The Filter Keywords controls are used by selecting one or more operations from their choice lists or entering a target (operand) in the Text box. After choosing or typing your entry, click the Add to Current Filter button to add these items to the Filter Keywords text entry box at its current insertion pointer.

The leftmost editable combo box contains the Boolean operators and, or, and not.

The Events box provides filtering terms that are complete and restrict the type of log event displayed. The following table describes the terms in the Events box. 

Table 9-4 Filter Terms of the Events Box

Term 

Description 

loglvl pkt

Allows displaying network packet-type events 

loglvl sess

Allows displaying network session-type events 

loglvl auth

Allows displaying events related to authentication operations 

loglvl app

Allows displaying events related to screen application (usually proxy) operations 

logapp activate

Allows displaying events related to policy activation. 

logapp auth

Allows displaying events from the authentication subsystem 

logapp compiler

Allows displaying events related to policy compilation 

logapp edit

Allows displaying events related to registry or policy editing 

logapp ftpp

Allows displaying events from the FTP proxy 

logapp ha

Allows displaying events related to HA operation 

logapp httpp

Allows displaying events from the HTTP proxy 

logapp iked

Allows displaying events related to the IKE daemon 

logapp log

Allows displaying events related to the logging facilities themselves 

logapp restore

Allows displaying events related to policy restoration 

logapp scan

Allows displaying events related to proxy content scanning and redirection 

logapp smtpp

Allows displaying events from the SMTP proxy 

logapp telnetp

Allows displaying events from the Telnet proxy 

logsev emerg

Allows displaying events of an emergency severity 

logsev alert

Allows displaying events of an alert severity or above 

logsev crit

Allows displaying events of a critical severity or above 

logsev err

Allows displaying events of an erroneous severity or above 

logsev warn

Allows displaying events of a warning severity or above 

logsev note

Allows displaying events of a notice severity or above 

logsev info

Allows displaying events of an informative severity or above (all events that are not of debug severity) 

logsev debug

Allows displaying events of a debug severity or above (all events) 

TheTerms box provides filtering terms most of which are incomplete and require an operand value, You type these in the Text box. They are added to the choice list of the Text box for reference so that you need not retype the value if you want to use it again. The following table describes the filter terms in the Terms box. 

Table 9-5 Filter Terms in the Terms Box

Term 

Description 

logwhy reason#

Restricts display to packets that have the given logging reason why code  

logiface iface

Restricts display to packets that arrived on the interface named iface

host hostname

Restricts display to events either from or to hostname

dst hostname

Restricts display to events destined for hostname

src hostname

Restricts display to events origination from hostname

port hostname

Restricts display to events related to the service svcname

dstport hostname

Restricts display to events targeted to the service svcname

srcport svcname

Restricts display to events originating from the service svcname

net netaddr

Restricts display to events either from or to the network whose number is netaddr

udp

Restricts display to events related to the UDP transport protocol 

tcp

Restricts display to events related to the TCP transport protocol 

icmp

Restricts display to packets of the ICMP control protocol 

rpc

Restricts display to packets of the RPC protocol 

The terms in italics are variables for which you must supply a value or values in the when you choose this term from the choice list. The values for the variable are as follow: