Policy Logging
Overview
Every flow observed by the Zero Trust Fabric is evaluated and the resulting action is logged into a centralized policy log, visible in Nile Control Center. The information recorded in the log includes:
Log Field | Description |
|---|---|
Timestamp | Time when flow was evaluated by Trust Engine |
Source Group | Name of the source policy group |
Source Group Type | Type of the source policy group (user, device, app) |
Destination Group | Name of the destination policy group |
Destination Group Type | Type of the destination policy group (user, device, app) |
Source IP | IP address of the source endpoint |
Source MAC | MAC address of the source endpoint |
Port | Target port on the destination endpoint |
Protocol | Protocol of traffic towards destination endpoint |
Service profile | Name of matching service profile |
Destination IP | IP address of the destination endpoint |
Destination MAC | MAC address of the destination endpoint |
Action | Action taken by Trust Engine: Allow, Deny, Forward upstream, |
When no policy exists for a given source/destination pair, the default-deny posture of the Zero Trust Fabric will deny traffic by default. The policy log will record this as a Deny action but will not identify the source and destination information. If explicit logging of the default Deny behavior for a source/destination pair is needed, then an explicit Deny policy should be created.