On the Subscription Dashboard page in WatchGuard Cloud or Dimension, you can see a high-level view of the activity for subscription services enabled on your Firebox for the date and time range you select. A separate tile appears for each service that has traffic for the selected date and time range.
Enable Logging
If security service statistics logging is not enabled, you must enable it in Policy Manager or Fireware Web UI.
To enable logging, from Policy Manager:
- Select Setup > Logging.
- Click Performance Statistics.
- Select the Security Services Statistics check box. Click OK.
- For all packet filters, in the Logging and Notification settings, select Send a log message for reports. For more information, go to Set Logging and Notification Preferences in Help Center.
- In the General Settings for all proxy actions, enable logging:
- In all APT Blocker actions, select the Log check boxes for threat levels. For more information, go to Configure APT Blocker in Help Center.
- In all DLP Sensor actions, select the Log check box. For more information, go to Configure DLP Sensors in Help Center.
- In the Gateway AntiVirus settings for a proxy action, select the Log check boxes for all Gateway AntiVirus actions. For more information, go to Configure Gateway AntiVirus Actions in Help Center.
- In the Intrusion Prevention settings, select the Log check box for threat levels with the Block and Drop actions. For more information, go to Configure Intrusion Prevention in Help Center.
- In all spamBlocker actions, select the Send a log message check box. For more information, go to Activate and Configure spamBlocker in Help Center.
- In all WebBlocker actions, select the Log check box for all categories and select the When a URL is uncategorized, Log this action check box. For more information, go to Configure WebBlocker Categories in Help Center.
To enable logging, from Fireware Web UI:
- Select System > Logging.
- On the Settings tab, select the Send Security Services Statistics to log file check box.
- For all packet filters, in the Logging and Notification settings, select Send a log message for reports. For more information, go to Set Logging and Notification Preferences in Help Center.
- In the General Settings for all proxy actions, enable logging for reports:
- In all APT Blocker actions, select the Log check boxes for threat levels. For more information, go to Configure APT Blocker in Help Center.
- In all DLP Sensor actions, select the Log check box. For more information, go to Configure DLP Sensors in Help Center.
- In the Gateway AntiVirus settings for a proxy action, select the Log check boxes for all Gateway AntiVirus actions. For more information, go to Configure Gateway AntiVirus Actions in Help Center.
- In the Intrusion Prevention settings, select the Log check box for threat levels with the Block and Drop actions. For more information, go to Configure Intrusion Prevention in Help Center.
- In all spamBlocker actions, select the Send a log message check box. For more information, go to Activate and Configure spamBlocker in Help Center.
- In all WebBlocker actions, select the Log check box for all categories and select the When a URL is uncategorized, Log this action check box. For more information, go to Configure WebBlocker Categories in Help Center.
For more information, go to
Where to Enable Logging for Reports in
Help Center.
Verify Logging is Enabled
To verify that security service statistics logging is enabled, from WatchGuard Cloud:
- Open Log Manager.
- From the view log type menu, select Statistics Logs.
Statistic logs show in the table when logging is enabled.
To verify that security service statistics logging is enabled, from Dimension:
- Select Tools > Log Manager.
- Select the Statistic filter.
Statistic logs show in the graph and table when logging is enabled.
Verify Log Server Connection Status
You can also verify the status of the connection to the Log Server in the Front Panel in Firebox System Manager and Fireware Web UI. The Front Panel shows the IP address of each log server the Firebox is connected to. If the Firebox cannot connect to a configured log server, an error message appears instead of an IP address.
To verify the log server connection status, from Firebox System Manager:
- From WatchGuard System Manager, select Tools > Firebox System Manager.
- In the Detail section, adjacent to Log Server, verify that the IP address of the primary Log Servers you added on each tab appear.
To verify the log server connection status, from Fireware Web UI:
- Select Dashboard > Front Panel.
- In the Servers list, adjacent to Log Server, verify that the address of the primary Log Servers you added on each tab appear.
- If the Firebox cannot connect to a configured log server, the status is Not Connected. To see more information about the connection error, hover over the adjacent icon.