Logging, SNMP, and Telemetry

Learn to enable system logging, SNMP, and Telemetry services on the SRX4700 Firewall of your network.

After you have completed the system configuration of user accounts and authentication methods, you can enable system logging, SNMP, and telemetry on the device.

The SRX4700 Firewall baseline configurations for logging, SNMP, and telemetry involves enabling essential logging for security events and system messages, basic SNMP for monitoring, and telemetry streaming for advanced analytics. This topic provides you the recommended minimal configurations.

Logging (Syslog and Security Logs)

System Logs

System logs and event logs ensure visibility into allowed or blocked flows, firewall health, and security events.

You can configure system logging to record system events, track configuration changes, and troubleshoot issues.

Basic logging captures system events, audit logs, and security policy actions. Start with local archiving and optional forwarding to a remote server.

This configuration below sets up local syslog archiving with structured data on SRX4700 Firewall and enables security event logging in event mode:

For log traffic information for a specific policy, see log (Security Policies).

Verify the logs configured:

Security Logs

For security logs (traffic logs) on the SRX4700 Firewall, we recommend to use the set security log mode stream command to send logs directly from the data plane to a remote syslog server through the revenue ports, avoiding overload on the Routing Engine.

  • Stream Mode—mode stream streams logs directly to external servers (example: set security log stream <name> host <IP>), ideal for high volume as it bypasses Routing Engine processing.
  • Event Mode—mode event or stream-event sends logs to the Routing Engine first, which can overwhelm the Routing Engine under high traffic; use set security log event-rate <limit> (example: 1500) to throttle.

Use the set security log mode stream and set security log report for on-box reporting to external servers. Stream mode supports UDP, TCP, and TLS protocols for secure transmission. You can configure up to 8 remote hosts to receive security logs simultaneously, providing redundancy and load distribution.

Best Practices

  • Use revenue ports (not fxp0 management interface) for routing to the syslog server.
  • Formats: binary (compact, for JSA or STRM), sd-syslog (structured), syslog, protobuf, or welf.
  • Example for TLS-secured stream:
  • SDC or Cloud Logs: stream sd-cloud-logs requires a valid log plan in Security Director Cloud (SDC).
  • Limits: Up to 8 streams on SRX/vSRX; configure per tenant for multi-tenant setups.

SNMP

SNMP provides device monitoring through MIBs.

This baseline configuration below sets up basic SNMP monitoring on SRX4700 Firewall with read-only community access, trap forwarding to a Network Management System (NMS), enables SNMPv2c (or SNMPv3 for enhanced security) with a community string and basic traps, and device identification details:

Verify the configuration using the show snmp statistics command.

Telemetry

Junos Telemetry enables you to stream device data from Juniper devices to external data collectors. This data can include information about traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behavior. Telemetry data is streamed over gRPC connections, and the connections can be initiated from a Juniper device or an external data collector.

The sample baseline configuration below enables basic streaming, gRPC telemetry services, and configures a Junos Telemetry (JT) sensor on SRX4700 Firewall for streaming data every 10 seconds:

Configuring Junos Telemetry (JT) on SRX4700

On the SRX4700, configure the Junos Telemetry (JT) using the services analytics hierarchy to enable gRPC-based streaming of operational data to external collectors.

Basic Configuration Steps

  1. Enable the analytics service using the set services analytics command.

  2. Configure a gRPC sensor (example for interface statistics).

  3. Set up the gRPC server (supports multiple servers with distinct ports/services).

    Enhance with TLS for security:

  4. Specify resource paths supported on SRX4700 (such as telemetry streaming).

    • /junos/events
    • /junos/task-memory-information/
    • /interfaces/
    • /components/
    • /network-instances/network-instance/protocols/protocol/bgp/
    • /network-instances/network-instance/protocols/protocol/isis/levels/level/
  5. Configure memory monitoring thresholds (optional, for enhanced telemetry).

  6. Commit the configurations and verify.

This configuration streams interface statistics, BGP and IS-IS metrics, and memory usage to external collectors. SRX4700 Firewall supports advanced features such as multiple gRPC servers and TLS in Junos OS Release 25.2R1 and later.

For more information, see Junos Telemetry User Guide.