Viewing the Event Log
The logs detail the date and the time the event occurred, and its type. If the event is a communication
attempt that was rejected by the firewall, the event details include the source and destination IP address, the
destination port, and the protocol used for the communication attempt (for example, TCP or UDP). If the
event is a connection made or attempted over a VPN tunnel, the event is marked by a lock icon in the VPN
column.
This information is useful for troubleshooting. You can export the logs to an *.xls (Microsoft Excel) file,
and then store it for analysis purposes or send it to technical support.
Note: You can configure the IP60 appliance to send event logs to a Syslog server.
For information, see Configuring Syslog Logging on page 424.
To view the event log
1. Click Reports in the main menu, and click the Event Log tab.
The Event Log page appears.
2. If an event is highlighted in red, indicating a blocked attack on your network, you can display
the attacker's details, by clicking on the IP address of the attacking machine.
The IP60 appliance queries the Internet WHOIS server, and a window displays the name of the entity
to whom the IP address is registered and their contact information. This information is useful in
tracking down hackers.
3. To refresh the display, click Refresh.
4. To save the displayed events to an *.xls file:
Click Save.
a.
A standard File Download dialog box appears.
218
Nokia IP60 Security Appliance User Guide