View Combine Firewall Logs
The Combine Firewall writes the connections it alerts on or blocks to the Combine_Firewall CloudWatch Log Group. For which connections appear in this Log Group, see Log Streams in View Combine Logs.
Steps
- Sign in to the AWS Console.
- Open the CloudWatch console.
- In the left pane, expand Logs and choose Log Groups.
- In the Log Groups window, choose the
Combine_FirewallLog Group (orCombine_<shard id>_Firewallif your Combine Deployment has a Shard ID). - Make sure the Log Streams tab is open at the bottom, and choose Search all log streams on the right. For real-time logs, choose Start Tailing instead.
- To highlight a string of interest, type it in the Highlight Term field. For example, to highlight the IP address
1.2.3.4, type1.2.3.4. - Look for log entries that contain
rejectorblock.
Filter for Blocked Traffic
The following filter pattern finds blocked traffic to a set of IP addresses:
{ ($.event.dest_ip = "1.2.3.4" || $.event.dest_ip = "5.6.7.8" || $.event.dest_ip = "9.10.11.12") && $.event.alert.action = "blocked" }
For more filter patterns and for CloudWatch Logs Insights, see Sample Queries and Use CloudWatch Logs Insights. To exempt a domain from the Combine Firewall, see Firewall Exception List.