Premium Services
Nile Trust Service
Policy Logging
1 min
overview every flow observed by the zero trust fabric is evaluated and the resulting action is logged into a centralized policy log, visible in nile control center the information recorded in the log includes log field description timestamp time when flow was evaluated by trust engine source group name of the source policy group source group type type of the source policy group (user, device, app) destination group name of the destination policy group destination group type type of the destination policy group (user, device, app) source ip ip address of the source endpoint source mac mac address of the source endpoint port target port on the destination endpoint protocol protocol of traffic towards destination endpoint service profile name of matching service profile destination ip ip address of the destination endpoint destination mac mac address of the destination endpoint action action taken by trust engine allow, deny, forward upstream, when no policy exists for a given source/destination pair, the default deny posture of the zero trust fabric will deny traffic by default the policy log will record this as a deny action but will not identify the source and destination information if explicit logging of the default deny behavior for a source/destination pair is needed, then an explicit deny policy should be created
