您可以使用 VMware vRealize Log Insight 查看 NSX-T Data Center 环境的安全流日志。

以下安全功能支持流量日志记录:
  • TLS 检查
  • 网关 IDPS
  • URL 筛选
注:

NSX-T Data Center 3.2.1 开始,TLS 检查和网关 IDPS 可在生产环境中使用,并且完全受支持。在 NSX-T Data Center 3.2.0 中,这些功能仅在技术预览模式下可用。有关详细信息,请参见NSX-T Data Center 发行说明

统一安全日志

所有安全垂直项都会在节点上的单个日志文件中生成统一安全流日志,并以统一安全日志格式保存这些日志。此单个日志将导出到为 VMware vRealize Log Insight 配置的 syslog 服务器。然后,VMware vRealize Log Insight 将处理日志,以使用 NSX-T 内容包提供进一步的日志管理、分析并显示日志。

在 vRealize Log Insight 上显示日志

在现有 NSX-T 内容包中添加了新的仪表板“NSX - 统一安全流日志”。此仪表板显示图表小组件,后者是安全流日志的可视化表示。

VMware vRealize Log Insight 的内容包是一个插件,其中包含与特定产品或日志集相关的仪表板、已提取的字段、保存的查询和警示。

NSX-T 内容包在 VMware vRealize Log Insight 商城上可用。

有关 VMware vRealize Log Insight 以及如何从内容包商城安装内容包的详细信息,请参见 “使用 VMware vRealize Log Insight 产品”文档中的从内容包商城安装内容包一章。

前 N 条和过去 X 小时

您还可以使用交互式分析和内容包查询 VMware vRealize Log Insight 中的事件,获取过去 X 小时内的前 N 条信息。

远程日志记录服务器

要将日志发送到远程日志记录服务器,必须分别在每个节点上为 NSX-T Data Center 设备和 Hypervisor 配置远程日志记录。

注: 要将日志发送到 syslog 服务器,您必须为 NSX-T Manager 上的特定规则启用日志记录。

有关详细信息,请参见配置远程日志记录

如果远程日志服务器不接收日志,请参见对 Syslog 问题进行故障排除

统一安全日志格式

在 Edge 节点上,统一安全流日志都存储在 /var/log/syslog 中。您可以用 root 用户身份登录,并使用 grep 命令搜索此文件以查找统一日志。例如:
cat /var/log/syslog | grep 'unified-logs'

日志消息示例:

TLS 检查
2021-10-12T09:00:46.192Z nsxedge-18734920-1-mps29 NSX 22621 SYSTEM [nsx@6876 comp="nsx-edge" 
subcomp="tls-proxy" s2comp="unified-logs" level="INFO"] {"event_type": "fw-flow-terminate-log", 
"event_trigger": ["fw-rule-log"], "origin": {"fw_type": "gateway", "fw_uuid": "79427614-4a0d-2692-032c-eb4692f717a9", 
"node_uuid": "ec11a626-f425-3bc2-671d-a656500003b2"}, "flow": {"start": "2021-10-12T09:00:46.723Z", 
"end": "2021-10-12T09:00:46.773Z", "ip_ver": "ipv4", "flow_id": "0x1e0000704f000018", 
"src_ip": "192.168.100.160", "src_port": 25700, "dest_ip": "1.1.5.10", "dest_port": 443, "proto": "TCP", "tcp_flags": "",
"bytes_toserver": 95, "bytes_toclient": 29873, "reason": "FIN-close", "final_action": "PASS"}, "fw": {"action": "PASS", "rule_id": 1002,
"direction": "", "rule_tag": ""}, "http": {"http_method": "", "hostname": "www.facebook.com", "url": "www.facebook.com/benign_pdf1.pdf", "scheme": "", "http_user_agent": "", "status": "",
"site_category": ""SOCIAL_NETWORK"", "site_reputation": "Trustworthy"},"tls_inspection": {"action": "PASS", "rule_id": 1008, "domain": "www.facebook.com", "cert_status": "ok", "tls_version_toserver": "TLSv1.2",
"cipher_to_server": "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", "reason": "", "tls_rule_tag": "TLS External Rule"}, "idps": {"action": "PASS", "rule_id": 1007,
"ids_profile_id": "00000000-0000-0000-0000-000000000000", "alert_event": ["SOCIAL_NETWORK"], "protocol_event": ["http"]}, "app_id": {"app": ""APP_HTTP", "APP_FACEBOOK", "APP_SSL""}
网关 IDPS
2021-11-11T04:07:37.489Z nsxedge-18866667-2-NAT-fc-3-nov NSX 27330 SYSTEM [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="unified-logs" level="INFO"]
 {"event_type": "fw-flow-terminate-log", "event_trigger": ["ids-rule-log"], "origin": {"fw_type": "gateway", "fw_uuid": "544ee558-fad0-e624-019f-e8e3e0472c91", 
"node_uuid": "dabf16c9-ec11-833c-0c00-8c832f771729"}, "flow": {"start": "2021-11-11T04:07:07.000Z", "end": "2021-11-11T04:07:37.000Z",
"ip_ver": "ipv4", "flow_id": "0xd44d00306e0a0004", "src_ip": "1.1.1.10", "src_port": 35714, "dest_ip": "10.142.7.1", "dest_port": 53,
"proto": "UDP", "tcp_flags": "FPW", "bytes_toserver": 297878, "bytes_toclient": 71, "pkts_toserver": 71, "pkts_toclient": 1, 
"reason": "FIN-close", "final_action": "PASS"}, "fw": {"action": "PASS", "rule_id": 2025, "direction": "", "rule_tag": ""},
"l7profile": {"entry_id": "00000000-0000-0000-0000-000000000000", "action": "PASS"}, 
"http": {"http_method": "", "hostname": "", "url": "", "scheme": "", "http_user_agent": "", "status": "", "site_category": "", 
"site_reputation": "UNKNOWN"}, "idps": {"action": "IDP_DETECT", "rule_id": 2028, "ids_profile_id": "9872e27a-ead4-4c93-af5f-4df1ec0c73e1", 
"alert_event": [], "protocol_event": []}, "app_id": {"app": ""APP_DNS""}}
URL 筛选
2021-11-08T08:30:59.208Z nsxedge-18866667-2-NAT-fc-3-nov NSX 9495 SYSTEM [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="unified-logs" level="INFO"]
{"event_type": "fw-flow-terminate-log", "event_trigger": ["fw-rule-log"], "origin": {"fw_type": "gateway", "fw_uuid": "544ee558-fad0-e624-019f-e8e3e0472c91",
"node_uuid": "dabf16c9-ec11-833c-0c00-8c832f771729"}, "flow": {"start": "2021-11-08T08:30:57.000Z", "end": "2021-11-08T08:30:59.000Z",
"ip_ver": "ipv4", "flow_id": "0x4001006c04000000", "src_ip": "1.1.1.10", "src_port": 43600, "dest_ip": "13.226.234.18", 
"dest_port": 80, "proto": "TCP", "tcp_flags": "FREW", "bytes_toserver": 54968, "bytes_toclient": 444, 
"pkts_toserver": 444, "pkts_toclient": 7, "reason": "FIN-close", "final_action": "PASS"}, "fw": {"action": "PASS", "rule_id": 1004, "direction": "",
"rule_tag": ""}, "l7profile": {"entry_id": "e9580107-2749-471c-be82-715d530bf4d4", "action": "PASS"},
"http": {"http_method": "", "hostname": "", "url": "espn.com/", "scheme": "", "http_user_agent": "", "status": "",
"site_category": ""SPORTS"", "site_reputation": "TRUSTWORTHY"}, "app_id": {"app": ""APP_HTTP", "APP_ESPN""}}