Monitoring & Reporting

Monitoring & Reporting

Barracuda SecureEdge offers multiple audit and reporting functionalities to help you monitor activities throughout your network. It includes logs, dashboards, reporting, log streaming, alerts, notifications profile, maintenance notifications, service health, AI security findings, and AI usage and activity trends.

Audit Log

The Audit Log contains all administrative actions and displays the user and the public IP address of the user who performs an action. It can be accessed in the Audit Log tab of the Cloud UI https://se.barracudanetworks.com. Actions performed directly on the Local Web UI are logged with the username root. You can also download the entries as a CSV file.

Log Files 

Barracuda SecureEdge appliances generate log files for the following system processes:

  • FW Activity Log

  • Threat Log

  • Web Log

  • SD-WAN Log 

Log files are stored and are accessible directly on the appliance. To limit the size of a single log file, the appliance creates a new log file for each service every four hours. All log files are stored in plain text in the system's /var/phion/logs directory. 

Format and Types

Log file entries are divided into the following segments:

  • Time – The time when an event has taken place. This indicator marks individual log entries.

  • Type – Shows the following types of the log files.

    • Warning – Uncritical log event (e.g., login to the system)

    • Error – Log event error (e.g., system calls or clock skew)

    • Fatal – System-critical log events.

    • Notice – Normal system log events.

    • Security – Security-relevant log events.

    • Panic – Marks critical log events compromising the system's functionality and stability.

  • TZ – Displays the UTC time zone offset compared to the local box time.

  • Message – Description of the log event.  

SecureEdge Logs

Barracuda SecureEdge provides logs to monitor activities across your network. On the SecureEdge Manager, you can view AI Risk logs, Content Inspection logs, Web Logs, Threat Logs, DNS Logs, Web Monitor Logs, Network Logs, ZTNA Device Connectivity, ZTNA Device Health, ZTNA Resource Access Logs, and Event Logs.

For more information on logs, see SecureEdge Logs.

Stream Log Files to Microsoft Azure

Log files can be easily streamed to a Log Analytics workspace in Microsoft Azure.  

azmonitor.png

 

Firewall Activity Log Action taken Source IP Source port Destination IP Destination port Firewall Threat Log Threat description Action taken Source IP Destination IP Destination port Protocol User name VPN User Accounting Log Event (login/logout) Tunnel name User name Peer Start time End time Duration Bytes in Bytes out SDWan Data Log Tunnel name Host name Transport state Sample timestamp Number of samples Effective upstream bandwidth minimum Effective upstream bandwidth average Effective upstream bandwidth maximum Effective downstream bandwidth minimum Effective downstream bandwidth average Effective downstream bandwidth maximum Latency minimum Latency average Latency maximum Usage standard upstream minimum Usage standard upstream average Usage standard upstream maximum Usage standard downstream minimum Usage standard downstream average Usage standard downstream maximum Usage non-delay upstream minimum Usage non-delay upstream average Usage non-delay upstream maximum Usage non-delay downstream minimum Usage non-delay downstream average Usage non-delay downstream maximum Barracuda Own Metrics SSL VPN clients Connections total Connections new Connections failed Connections dropped Connections blocked Forwarding connections total Forwarding connections new Site-to-site VPN tunnels up Site-to-site VPN tunnels down Client-to-site VPN tunnels Protected IPS IPS hits Packets total Packets in Packets out Bytes total Bytes in Bytes out Metered bytes total Used memory Free memory Load Generic Performance Metrics Hard disk i/o measurements RAM usage Network interface statistics CPU usage File system usage Temperature data

Syslog Streaming

The Barracuda SecureEdge Manager allows administrators to configure syslog streaming.

sysstream.png

For more information, see How to Configure Syslog Streaming in SecureEdge.

Notifications

Barracuda SecureEdge allows you to create notification profiles for administrative and system events across all workspaces. Notifications alert users and administrators and can be configured for user preferences.

notification-profile.png

 

For more information, see Notifications.

Reports

SecureEdge can be generate and email reports. A summary report offers a concise overview of key data. You can also schedule reports.

SEReports.png

For more information, see SecureEdge Reports.

Further Information

 


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.