Changing management log levels
Complete the following steps to change management log levels.
About this task
The management log (balancer.log and controller.log) levels are initially configured in ase.conf file by setting log_level to one of the following five values:
-
fatal -
error -
warning -
info -
debug
|
The default value is |
Steps
-
To change the log level of management logs during run-time, use the
log_levelcommand.The
log_levelcommand works in an identical way for both sideband and inline API Security Enforcer (ASE) modes. -
In an ASE cluster set up, run the
log_levelcommand with thewarnoption on all the ASE nodes in the command-line interface (CLI).Example:
The following is an example CLI output of the
log_levelcommand to change the log level towarning:#./bin/cli.sh -u admin -p admin log_level warn
Result:
The change in log-level is also recorded in Audit logs.
-
Verify the current log level by using the ASE
statuscommand.Example:
#./bin/cli.sh -u admin -p status API Security Enforcer status : started mode : inline http/ws : port 8080 https/wss : port 8443 firewall : enabled abs : disabled, ssl: enabled abs attack : disabled audit : enabled ase detected attack : disabled attack list memory : configured 128.00 MB, used 25.60 MB, free 102.40 MB log level : warn timezone : local (MST)