show session-logger ssl config

Prev Next

Displays whether the SSL Session Log module can generate logs on the Network Security appliance, the status of the session log fields for SSL interception traffic, and the maximum number of archived log fil Network Security User Guide.

Syntax

show session-logger ssl config

Parameters

None

Output fields

The following table describes the output fields for the show session-logger ssl config command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Status

Whether the SSL Session Log module is enabled to generate logs on the Network Security appliance.

Max File Rotation Limit

Maximum number of archived log files you want to store on the Network Security appliance for SSL flows. The default number of archived log files that can be rotated is 5.

Field Name

Log field you want to log to the Network Security appliance. Valid session log fields are:

  • cs_cipher_suite—Cipher suite associated with client-side connections.

  • rs_cipher_suite—Cipher suite associated with server-side connections.

  • rs_cert_status—Server-side certificate that is logged.

  • cs_bytes—Client-side bytes transferred during the connection and logged.

  • rs_bytes—Server-side bytes transferred during the connection and logged.

  • time_taken—Date and time that the connection event is logged.

Example

The following example displays that three session log fields are enabled for SSL interception traffic.

hostname (config) # show session-logger ssl config

Feature Status :  enabled
Max File Rotation Limit : 5

Field Name      : Status
------------------------
cs_bytes        : ONcs_cipher_suite : ON
rs_bytes        : OFF
rs_cert_status  : OFF
rs_cipher_suite : ON
time_taken      : OFF

User role

Administrator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.2.1.