Logging: Enhanced log searching tools (Better search & filter)
I would like to see better and more granular search options/filters for log searching.
What if I'm interesting in a host only when it's a source and only when it goes to port 25 on another host. Today I can only give a simple search term and get way to much data back for it to be useful fast without spending too much time looking through the result.
This feature will be part of the UTM 9.2 release which will enter public beta in September 2013 for GA release in November. Stay tuned!
All log views (live and archived) should support filtering with a minimum of, source IP, destination IP, source port, destination port. Sophos touts UTM as a TMG replacement, but it is sorely lacking in this area. On the TMG 2010, all data - proxy and firewall is logged to a database and can be filtered on virtually any criteria that is logged with a few clicks. And the same interface is used for both Live and archived data. And with one click the filtered data could be dumped to a CSV file for additional parsing.
Did this happen in 9.2? Logging is still a huge pain; it's nearly impossible to find what you are looking for. Source and Destination IP and Port seem like standard features in many other firewalls, and is nearly a requirement. We cant even export the logs to XLS/CSV and sort them that way. It's a huge pain.
I would add "saved searches", so you can have already predefined searches. As well as, chained searches. Protocol + IP / Mac address + port + Interface. Thanks.