01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8<br />

Monitoring<br />

Logging<br />

Modify a default logging rule to record key words<br />

You can modify a default logging rule that writes entries into the Access Log to include the key words<br />

that led to the blocking of text with “bad” key words.<br />

To modify this rule:<br />

1 Go to Policy | Rule Sets.<br />

2 From the rule sets menu, select Log Handler.<br />

3 Expand the Default log handler rule set and select the nested Access Log rule set. The rules of this<br />

rule set appear on the settings pane.<br />

4 Select the Write access.log rule and click Edit. The Edit Rule window opens.<br />

5 Select Events and in the Events field, select the Set User-Defined.logLine = ... event.<br />

6 Click Edit. The Edit Set Property window opens.<br />

7 Click Add. The Please Enter a String window opens.<br />

8 Click Property and from the list of properties, select List.LastMatches.<br />

9 Click OK. The window closes and the List.LastMatches property is added to log line that is written into<br />

the Access Log.<br />

10 Click Add again, select Value in the window, and in the input field type the following string: “ ”<br />

(whitespace embedded in quotes).<br />

11 Click OK to close the Edit Set Property window.<br />

12 Click Finish to close the Edit Rule window. The modified rule appears on the settings pane.<br />

13 Click Save Changes.<br />

After modifying the rule in this way, the log line for the Access Log contains a string that is the value of<br />

the List.LastMatches property.<br />

If a blocking rule blocks access to text based on a comparison to a list of bad key words, this string<br />

contains the matching key word or words that led to the blocking.<br />

For more information, see Use of a property in a logging rule to record blocking key words.<br />

290 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!