System Log

The System Log page shows a list of all the system events that occurred in the system. For example, Policy turned on, Policy edited, Event Resolved and so on. This log includes both user-initiated events as well as automatically occurring system events (for example, Policy turned off automatically because of too many hits). This log does not include policy-generated events (which are shown on the Events page). You can export the logs as a CSV file. You can also configure the system to send the System Log events to a Syslog server.

The following information is available for each logged event:

Parameter Description
Time The time and date when the event occurred.
Event A brief description of the event.
Username The name of the user that initiated the event. For events that occur automatically, there is no username.

Send System Log to a Syslog Server

To configure the system to send system events to a Syslog server:

  1. Go to Local Settings > System Log.

  2. In the header bar, click Select syslog server.

    A drop-down list of servers appears.

    Note: To add a Syslog server, see Syslog Servers.
  3. Select the desired server.

    OT Security EM sends the system log events to the specified Syslog server.