This article explains how to use the Cato Management Application to export logs for your account from the cloud log storage (AWS S3 bucket).
You can export zipped files of event logs to integrate with a SIEM system and/or store in a remote location (for example, for regulatory or archival purposes). The log files are exported to secure storage in the AWS bucket (an S3 bucket), and each account is securely separated from other accounts. Cato stores the logs in the S3 bucket for 7 days. The Cato Management Application lets you download a script and when you run the script it downloads the zipped log files from AWS to a local file.
To show the Logs Exporter screen:
-
From the navigation menu, click Administration > Log Exporter. The Log Exporter screen opens.

You can choose to export the logs in CEF or JSON format, and select which types of events you are exporting.
To configure the settings for the exported logs:
-
From the navigation menu, click Administration > Log Exporter. The Log Exporter screen opens.
-
Select the file format for the exported logs, from Format. Option type is CEF or JSON.
-
Select the types of events to export in the Types to log section. Types include:
-
Audit Trail - Admin changes made in the Cato Management Application
-
Health - Logs related to connectivity for LAN monitoring, sites, and VPN Clients in the account
-
Security - Logs generated by Threat Protection and firewall engines
-
System - Logs related to LDAP, User Awareness, license, and users accounts
-
-
Click Save. The Log Exporter settings are configured.
The Cato Management Application provides a Bash script file that connects to the Amazon S3 bucket for your account and downloads the logs files to your local host.
We recommend that you run the script automatically at scheduled intervals. You can also run the script manually as required.
Note
Note: Modifying the client script is not supported.
To download the client script from the Cato Management Application:
-
From the navigation menu, click Administration > Log Exporter. The Log Exporter screen opens.
-
Click Download Client Script.
The client script includes a unique access token for your account. For increased security, you can regularly change the access token used by the client script. Changing the access token also creates a new secure location where Cato Networks stores the log files.
After you change the access token, click Download Client Script to download the client script with the new access token. Wait about 15 minutes for the new access token to update in the cloud before you run the new client script. You can still access the previous logs with the script that includes the previous access token was changed.
Comments
0 comments
Please sign in to leave a comment.