Skip to main content
Aviatrix PaaS and all of its managed gateways can be configured to forward their logs to log management systems. This section describes Aviatrix log keywords that can be identified by log management systems for further analysis.

Aviatrix Log Keywords

The following types of Aviatrix log keywords can be identified by the Log Management System for further analysis:

AviatrixRule:

You need to configure security policies to see AviatrixRule log. Logs with this prefix come from each gateway managed by Aviatrix PaaS. Any packet that triggers the security policy rule will generate a log record of this type with the first 100 bytes of the packet. It contains the information such as gateway IP address, inbound and outbound interface, MAC address, TTL value, protocol name, source IP address, destination IP address and packet length. An example for a deny rule event is shown below. The log event prefix is “AvxRl gw1 D:”, where the gateway name is gw1, “D” represents Drop.
Another example for an accept rule event is shown below. The log event prefix is “AvxRl StatefulGW2 A:”, where the gateway name is StatefulGW2, “A” represents Accept.

AviatrixGwMicroSegPacket:

You need to configure Distributed Cloud Firewall (DCF) micro-segmentation policies to see AviatrixGwMicrosegPacket logs. Logs with this prefix come from your configured DCF micro-segmentation policies. These logs contain the following information:
  • timestamp
  • source IP
  • destination IP
  • protocol (for example, ICMP or TCP)
  • port number
  • if a policy is enforced
  • if a policy was allowed or denied
  • gateway name
  • policy ID
A DCF micro-segmentation log example is shown below:

AviatrixGwNetStats:

Logs with this prefix come from each gateway managed by Aviatrix PaaS. These logs are sampled every minute and give details about gateway network interface. Two example logs:

AviatrixGwSysStats:

Logs with this prefix come from each gateway managed by Aviatrix PaaS. These logs are sampled every minute and give details about gateway memory, cpu and disk load. Two example logs:

AviatrixTunnelStatusChange

Logs with this prefix come from Aviatrix PaaS whenever a tunnel status changes. old_state means old state of the tunnel, and new_state is the new changed state of the tunnel. Example log:

AviatrixCMD

Logs with this prefix come from Aviatrix PaaS whenever a CLI command is issued. It contains information on the CLI command that was issued, the results of the execution, reason a message if there is a failure and who issued the command. Example log:

AviatrixBGPOverlapCIDR

Log messages with this prefix come from Aviatrix PaaS whenever it detects overlapping CIDRs between on-prem learned and Spoke VPC CIDRs. Example log:

AviatrixBGPRouteLimitThreshold

Log messages with this prefix come from Aviatrix PaaS whenever it detects that total BGP routes exceed the 80 routes. (AWS VGW has a total 100 route limit.) Example log:

AviatrixGuardDuty

Log messages with this prefix come from Aviatrix PaaS whenever it receives an alert message from AWS GuardDuty. Example log:

AviatrixFireNet

Log messages with this prefix come from Aviatrix PaaS whenever a firewall instance state changes. Example log:

AviatrixGatewayStatusChanged

These log messages will be seen from Aviatrix PaaS syslogs when a gateway’s status changes. Example log: