<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>WAF log after pentestig</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/133074/waf-log-after-pentestig</link><description>Hello, 
 We did a Pentesting for 5 days on your Website which are behind XG WAF Firewall. 
 In the firewall rule, Advanced, Protection, We create a protection policy with is in Monitor Mode 
 So now I would like to see if we have log of the Pentesting</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490282?ContentTypeID=1</link><pubDate>Thu, 03 Mar 2022 04:58:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4c7047b0-cc66-4dc8-a81e-cfc7cec36730</guid><dc:creator>Vishal_R</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/service-informatique2"&gt;Service Informatique2&lt;/a&gt;&amp;nbsp;Unfortunately no direct settings are available to increase the size of log files. No signature found can appear due to the URL hardening feature. You may do the needful as per below KBA:&lt;br /&gt;&lt;br /&gt;Sophos Firewall: Error &amp;quot;No signature found&amp;quot; in WAF.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://support.sophos.com/support/s/article/KB-000036415?language=en_US"&gt;https://support.sophos.com/support/s/article/KB-000036415?language=en_US&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For the Form hardening related details you may check some old discussions in the community if that helps to fix your error:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://community.sophos.com/sophos-xg-firewall/f/discussions/119688/web-server-protection-form-hardening-anomaly-exception/434778"&gt;community.sophos.com/.../434778&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490237?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2022 16:28:27 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3dbf9f01-dd71-4ccb-8a09-2463413d7a01</guid><dc:creator>Service Informatique2</dc:creator><description>&lt;p&gt;Vishal I have some questions :&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Can I increase the size of the reverseproxy.log.0 ?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;In the log,I have many line like :&lt;/p&gt;
&lt;p&gt;[Wed Mar 02 13:51:05.978373 2022] [cookie:error] [pid 16671:tid 140440103700224] [client xx.xx.xx.xx:53022] No signature found&lt;/p&gt;
&lt;p&gt;And :&lt;/p&gt;
&lt;p&gt;[Wed Mar 02 12:19:02.598863 2022] [form_hardening:error] [pid 25351:tid 140439994595072] [client xx.xx.xx.xx:55719] Form validation failed: Received unhardened form data, referer: https://URL/&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Can I do some exceptions for Website ?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490225?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2022 13:26:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fe3c2401-1ed8-4292-8b5e-9d4bac33d8cb</guid><dc:creator>Service Informatique2</dc:creator><description>&lt;p&gt;Thank for your quick answer &lt;/p&gt;
&lt;p&gt;I&amp;#39;ve downloaded the reverseproxy.log.0&lt;/p&gt;
&lt;p&gt;220 000 lines but ony one day of history.&lt;/p&gt;
&lt;p&gt;I think I have too many information in logs...&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490224?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2022 13:17:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d816c65f-ca09-43f2-a214-664eed01dcd4</guid><dc:creator>Vishal_R</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/service-informatique2"&gt;Service Informatique2&lt;/a&gt;: Yes too old logs will not be there as all log file has limited storage logic to avoid disk filling up&amp;nbsp;problem and the logline will be rotated automatically. If an appliance is a higher model then it may contain the &amp;quot;log.0&amp;quot; as well for that service log ( example - reverseproxy.log.0).&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490223?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2022 13:07:33 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:15c94569-df18-4589-a00d-60bc95e30bde</guid><dc:creator>Service Informatique2</dc:creator><description>&lt;p&gt;Hello, thanks for you reponse. &lt;/p&gt;
&lt;p&gt;I&amp;#39;ve download localy the reverseproxy.log on my computer.&lt;/p&gt;
&lt;p&gt;But I have only the log for last one hour. And we have 36000 lines !&lt;/p&gt;
&lt;p&gt;So I can&amp;#39;t see log a month ago...&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490195?ContentTypeID=1</link><pubDate>Wed, 02 Mar 2022 05:50:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6ca5e393-1409-4c27-828e-ac09e2bdf7d7</guid><dc:creator>Vishal_R</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/service-informatique2"&gt;Service Informatique2&lt;/a&gt;&amp;nbsp;: You may copy or download the logs in the local system and then may analyze them in notepad ++ or may use grep or vi editors to see the response code status for URLs submitted to WAF.&lt;br /&gt;&lt;br /&gt;You may also check rule id which has triggered anomaly for any URLs and you may check those have been false positive or true detection etc with your Internal server team.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://support.sophos.com/support/s/article/KB-000035562?language=en_US#Infrastructure-rules"&gt;support.sophos.com/.../KB-000035562&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: WAF log after pentestig</title><link>https://community.sophos.com/thread/490154?ContentTypeID=1</link><pubDate>Tue, 01 Mar 2022 16:48:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:9cb2820b-d92d-480d-aef4-8752fccff915</guid><dc:creator>Service Informatique2</dc:creator><description>&lt;p&gt;My policy settings :&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/126/pastedimage1646153270884v1.png" alt=" " /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>