Skip to main content

Logs

Operation & Analytics > Logs shows the system log of the unit: messages from the firewall, the services, the network and the kernel.

Reading the log

  • Choose how many lines to load.
  • Turn wrap lines on to see long messages without scrolling sideways.
  • Use the search box to keep only the lines that match. The search accepts regular expressions.
  • Turn on follow to watch new messages as they arrive.

Useful searches

GoalSearch for
Blocked packetsthe name of the zone, or the log prefix used by the rule
VPN problemsopenvpn, charon or wireguard
DHCP activitydnsmasq-dhcp
Threat Shield IP blocksbanIP
Update or registration problemsthe name of the service, for example ns-plug

Keeping logs across reboots

By default the log lives in memory and is lost on reboot. To keep a copy, attach a disk or a USB drive and configure it in Infrastructure > System, in the Storage tab. The unit then also writes the logs to that device. See System.

When a unit is connected to a controller, logs are also transmitted to it, see Central management.

From the command line

The same log is available over SSH with logread. See Command line and FAQ.