Using mlog dashboard
There're two ways for us to view logs on mbox:
- view real-time local logs from console
- view logs from web GUI (log collector)
1. View local logs
mbox is by default enabled with local logging, to view locally generated logs (usually for troubleshooting purpose), issue below command:
mbox# show security logging local
Info: showing system local logs. use CTL+C to stop
Oct 14 23:22:06 zydev kernel: [3964398.563219] mboxfw-permit:IN=eth0 OUT= MAC=00:0c:29:44:8b:f8:00:0c:29:f2:fd:c6:08:00 SRC=10.99.1.3 DST=10.65.19.9 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=14154 DF PROTO=TCP SPT=50467 DPT=22 WINDOW=14600 RES=0x00 SYN URGP=0
Oct 14 23:22:31 zydev kernel: [3964422.848630] mboxfw-permit:IN=eth0 OUT= MAC=00:0c:29:44:8b:f8:00:0c:29:f2:fd:c6:08:00 SRC=10.99.1.3 DST=10.65.19.9 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=19492 DF PROTO=TCP SPT=50468 DPT=22 WINDOW=14600 RES=0x00 SYN URGP=0
Oct 14 23:28:15 zydev kernel: [3964766.693619] mboxfw-permit:IN=eth0 OUT= MAC=00:0c:29:44:8b:f8:00:0c:29:f2:fd:c6:08:00 SRC=10.99.1.3 DST=10.65.19.9 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=40692 DF PROTO=TCP SPT=50470 DPT=22 WINDOW=14600 RES=0x00 SYN URGP=0
- This command only shows real-time logs, for troubleshooting purposes. mbox doesn't keep any historical local logs. If we need historical logs, we have to export logs to an external log server/collector, discussed in this section.
- if we want to view firewall logs etc from local console/ssh, we still need to enable access logging, discussed in this section. But don't output/export to an external server.
- if an mbox is configured as a log client (export logs out to external log collector), the exported logs will not appear in this command. We need to view exported logs from the log server/collector.
- if an mbox is configured as a log collector, its local logs will not show up in this command, we need to view local logs from web GUI (see next section)
- use CTL+C to stop this command output.
2. View logs from web GUI (Log collector)
When mbox is configured as a log collector, it comes with intuitive logviewer GUI for administrators to view live logs, search historical records and export out log results etc.
There're two ways to access logviewer:
- Accessed from mfusion portal. Logon to mfusion portal, from dashboard, click on mbox logger host and select "mbox-logviewer" menu.
- Direct access. From local LAN connection, access to logger via https://mbox-lan-ip/logviewer. (NOTE: Make sure firewall-input rule permits tcp/80/443)
NAGIVATING LOGVIEWER GUI
There're a few menu for logview for different viewing objectives.
- "Realtime Logs" shows the latest incoming raw logs. It's auto-refreshed/updated every 5 seconds by default, however It's possible to change/adjust the interval manually. We can also filter by different contents to only see the "interesting" logs.
- "Historical Logs" allow administrator/operator to search historical logs based on different filtering criterion, and it's possible to export and print the search results.
- "Users" allows administrator to create support multiple accounts for operators.