How to enable debug logs in RSA Web Threat Detection
Originally Published: 2017-06-14
Article Number
Applies To
RSA Version/Condition: 6.0, 6.1, 6.2
Platform: UNIX
Issue
Resolution
- Set the parameter to write in different file so that logs for other services are not affected.
- Open the file /etc/rsyslog.conf with the vi editor and add the new setting, as shwon below.
# Setting WTD to write to local4 local4.*/var/log/wtdlocal4
- Open the file /etc/rsyslog.conf with the vi editor and add the new setting, as shwon below.
- Navigate to the /var/opt/silvertail/etc/conf.d/ directory.
- Look for the process name for which logging needs to be changed and navigate inside the respective folder. For instance, if we are looking to change logging level for mitigator the folder name would be Mitigator-0.
- In this folder there will be a <ProcessName>.conf file. Open this file with the vi editor.
- Once the file is opened, look for section which is similar to the text below.
<logger priority="INFO" facility="user" context="0" />
- Change the parameter for priority from "INFO" to "DEBUG" and facility from “user” to “local4” or any other parameter as set in Step 1. The new configuration should look similar to the example below.
<logger priority="DEBUG" facility="local4" context="0" />
- Save the file and exit the vi editor.
- Restart the syslog service (rsyslog) and then the process for which the changes are being made.
Once restart is done, the logs for this particular process will be written in DEBUG mode in the /var/log/wtdlocal4 file.
This would also ensure that other services are not affected.
Notes
- AnnoDb
- Cassandra
- ScoutProxy
- SiteProxy
Related Articles
ACM-100162 || PV_USER_ALL_ACCESS view does not include custom attributes post 7.1.1 installation 12Number of Views RSA-2024-03: RSA Governance and Lifecycle Security Update for SUSE Linux Enterprise Server Vulnerabilities 234Number of Views RSA-2026-04: RSA Governance and Lifecycle Security Update for SUSE Linux Enterprise Server Vulnerabilities 66Number of Views Determining the patch level for RSA Authentication Manager servers 530Number of Views RSA G&L Community Exchange Overview and FAQs 151Number of Views
Trending Articles
How to delete old or pending certificate signing requests for RSA Authentication Manager console or virtual host replaceme… Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to import CA signed console cert from AM 8.x primary into a new primary with same FQDN How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings.
Don't see what you're looking for?