Logging, SNMP, and Telemetry
Learn to enable system logging, SNMP, and Telemetry services on the SRX4700 Firewall of your network.
After you have completed the system configuration of user accounts and authentication methods, you can enable system logging, SNMP, and telemetry on the device.
The SRX4700 Firewall baseline configurations for logging, SNMP, and telemetry involves enabling essential logging for security events and system messages, basic SNMP for monitoring, and telemetry streaming for advanced analytics. This topic provides you the recommended minimal configurations.
Logging (Syslog and Security Logs)
System Logs
System logs and event logs ensure visibility into allowed or blocked flows, firewall health, and security events.
You can configure system logging to record system events, track configuration changes, and troubleshoot issues.
Basic logging captures system events, audit logs, and security policy actions. Start with local archiving and optional forwarding to a remote server.
This configuration below sets up local syslog archiving with structured data on SRX4700 Firewall and enables security event logging in event mode:
set system syslog archive files 2 set system syslog file syslog any any set system syslog file syslog archive size 10000000 set system syslog file syslog structured-data set security log cache set security log mode event # Or 'stream' for remote forwarding commit
For log traffic information for a specific policy, see log (Security Policies).
Verify the logs configured:
show log syslog show security log
Security Logs
For security logs (traffic logs) on the SRX4700 Firewall, we recommend to use the
set security log mode stream command to send logs directly from the
data plane to a remote syslog server through the revenue ports, avoiding overload on the
Routing Engine.
- Stream Mode—
mode streamstreams logs directly to external servers (example:set security log stream <name> host <IP>), ideal for high volume as it bypasses Routing Engine processing. - Event Mode—
mode eventorstream-eventsends logs to the Routing Engine first, which can overwhelm the Routing Engine under high traffic; useset security log event-rate <limit>(example: 1500) to throttle.
Use the set security log mode stream and set security log
report for on-box reporting to external servers. Stream mode supports UDP, TCP,
and TLS protocols for secure transmission. You can configure up to 8 remote hosts to
receive security logs simultaneously, providing redundancy and load distribution.
set security log utc-timestamp set security log mode stream set security log format sd-syslog set security log report set security log source-interface et-1/1/1 set security log transport set security log stream sd-cloud-logs category all set security log stream sd-cloud-logs host srx.sdcloud.juniperclouds.net set security log stream sd-cloud-logs host port 6514 set security log stream sd-cloud-logs transport division line-based set security log stream sd-cloud-logs transport protocol tls set security log stream sd-cloud-logs transport tls-profile syslog-profile
Best Practices
- Use revenue ports (not fxp0 management interface) for routing to the syslog server.
- Formats:
binary(compact, for JSA or STRM),sd-syslog(structured),syslog,protobuf, orwelf. - Example for TLS-secured stream:
set security log mode stream set security log format sd-syslog set security log source-interface <interface> set security log stream <name> host <IP> set security log transport protocol tls
- SDC or Cloud Logs:
stream sd-cloud-logsrequires a valid log plan in Security Director Cloud (SDC). - Limits: Up to 8 streams on SRX/vSRX; configure per tenant for multi-tenant setups.
SNMP
SNMP provides device monitoring through MIBs.
This baseline configuration below sets up basic SNMP monitoring on SRX4700 Firewall with read-only community access, trap forwarding to a Network Management System (NMS), enables SNMPv2c (or SNMPv3 for enhanced security) with a community string and basic traps, and device identification details:
[edit] set snmp community public authorization read-only set snmp trap-group trap-to-server targets 192.0.2.1 # Replace with your NMS IP set snmp trap-group trap-to-server version v2 set snmp location "SRX4700-DC1" set snmp contact admin@example.com commit
Verify the configuration using the show snmp statistics command.
Telemetry
Junos Telemetry enables you to stream device data from Juniper devices to external data collectors. This data can include information about traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behavior. Telemetry data is streamed over gRPC connections, and the connections can be initiated from a Juniper device or an external data collector.
The sample baseline configuration below enables basic streaming, gRPC telemetry services, and configures a Junos Telemetry (JT) sensor on SRX4700 Firewall for streaming data every 10 seconds:
Configuring Junos Telemetry (JT) on SRX4700
On the SRX4700, configure the Junos Telemetry (JT) using the services
analytics hierarchy to enable gRPC-based streaming of operational data to
external collectors.
Basic Configuration Steps
Enable the analytics service using the
set services analyticscommand.Configure a gRPC sensor (example for interface statistics).
set services analytics sensor interface name int-sensor resource /interfaces/ set services analytics sensor interface name int-sensor stream-name int-stream set services analytics sensor interface name int-sensor server grpc server-name grpc-server
Set up the gRPC server (supports multiple servers with distinct ports/services).
set services analytics server grpc server-name grpc-server port 50051 set services analytics server grpc server-name grpc-server stream-input grpc-stream
Enhance with TLS for security:
set services analytics server grpc server-name grpc-server tls-profile <profile-name>
Specify resource paths supported on SRX4700 (such as telemetry streaming).
/junos/events/junos/task-memory-information//interfaces//components//network-instances/network-instance/protocols/protocol/bgp//network-instances/network-instance/protocols/protocol/isis/levels/level/
Configure memory monitoring thresholds (optional, for enhanced telemetry).
set system monitor memory process (minor/major/critical)-event threshold <process-name> memory-limit <threshold>
Commit the configurations and verify.
commit show services analytics show services analytics sensor status
This configuration streams interface statistics, BGP and IS-IS metrics, and memory usage to external collectors. SRX4700 Firewall supports advanced features such as multiple gRPC servers and TLS in Junos OS Release 25.2R1 and later.
For more information, see Junos Telemetry User Guide.