Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

FAQ: Can 'Top Layer AppSwitch' log files be analyzed?

Expand / Collapse


This article applies to:

  • WebTrends Firewall Suite 4.X
  • Security Reporting Center 2.X
  • Top Layer AppSwitch

Question:

Can 'Top Layer AppSwitch' log files be analyzed?

Reply:

The 'Top Layer AppSwitch' device has the ability to generate log files in the format called WELF (WebTrends Enhanced Log Format).  The log file must be in this format for Firewall Suite or Security Reporting Center to properly run analysis. A sample of the WELF format is provided below:

id=firewall time="2003-07-01 06:30:09" fw=192.168.1.1 pri=6 proto=http src=192.168.1.1 dst=10.1.1.1 dstname=domain.com arg=/brand/images/logo_pimg.gif op=GET result=304 rcvd=1036
id=firewall time="2003-07-01 06:30:09" fw=192.168.1.1 pri=6 proto=http src=192.168.1.1 dst=10.1.1.1 dstname=domain.com arg=/transparent.gif op=GET result 0 sent=546

Notes:

For more information regarding WELF please see the following articles:

This article was previously published as:
NETIQKB33984

To contact LevelBlue about this article or to request support:


Rate this Article:
     
Tags:

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.