Manage FireCluster Logging in WatchGuard Cloud

Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes

After you add a FireCluster to WatchGuard Cloud, the FireCluster sends log messages to WatchGuard Cloud. FireCluster logging is enabled by default. You can view log messages in WatchGuard Cloud and create search queries to find FireCluster events.

To send log messages to a Dimension or a syslog server, see Configure Log Server Settings for Cloud-Managed Fireboxes.

Disable Logging

If you disable logging, the FireCluster remains connected to WatchGuard Cloud but does not send log messages.

To disable FireCluster logging to WatchGuard Cloud:

  1. Log in to your WatchGuard Cloud account.
  2. Select Configure > Devices.
  3. Select the cluster.
  4. In the FireCluster Logging section, disable Logging.
    The FireCluster immediately stops sending log messages to WatchGuard Cloud.

Screen shot of the FireCluster logging slider

Enable Logging

To enable FireCluster logging to WatchGuard Cloud:

  1. Log in to your WatchGuard Cloud account.
  2. Select Configure > Devices.
  3. Select the cluster.
  4. In the FireCluster Logging section, enable Logging.
    The FireCluster sends log messages to WatchGuard Cloud.

Screen shot for FireCluster status information, FireCluster logging, and FireCluster removal

View and Search Logs

To view FireCluster log messages in WatchGuard Cloud:

  1. Log in to your WatchGuard Cloud account.
  2. Select Monitor > Devices.
  3. In the Logs section, click Log Manager.
  4. From the drop-down list, select Event Logs or All Logs. FireCluster log messages are typically events.

Screen shot of the log type drop-down menu

For more information about Log Manager, see Log Manager (WatchGuard Cloud).

To search the logs for FireCluster events:

  1. Log in to your WatchGuard Cloud account.
  2. Select Monitor > Devices.
  3. In the Logs section, click Log Search.
  4. From the drop-down list, select All Logs.
  5. To find cluster-related messages, you can create simple or complex search queries. For example:
  • Specify keywords such as cluster*, master*, or failed over. You can specify basic Boolean operators between words.
    Screen shot of an example search for one keyword
    Screen shot of an example search for multiple keywords
  • Specify a cluster-related process ID such as crd or cvd.
    Screen shot of an example search for a process ID
  • Specify a custom date and time range.
    Screen shot of an example search for a custom date and time range
  • Combine search query methods. For example, specify a custom date and time range and the process IDs crd, cvd, and networkd.
    Screen shot of an example search that combines multiple search methods
  1. To save your search results to a .CSV file, click .

For more information about search queries, see Log Search (WatchGuard Cloud).

Example Log Messages

FireCluster Reboot

After a cluster master reboot, event messages appear in the log that describe the cluster member role change:

  • Member [serial number] changed role to backup sync
  • Cluster A/P role successfully changed from idle to backup master
  • Cluster member [serial number] changed role from backup master to master
  • Master [serial number] failed over to member [serial number]
  • Member [serial number] is now master
  • Member [serial number] changed role to master
  • Cluster A/P role successfully changed from backup master to master
  • Failed over from backup to master
  • Cluster member [serial number] changed role from backup master to master

After a backup master reboot, these event messages appear in the log:

  • [Interface name] Interface link status changed to down
  • Monitored interface [interface name] link is down
  • Master [serial number] detected loss of heartbeat from member [serial number], cluster channel is up
  • [Interface name] Interface link status changed to up
  • Monitored interface [interface name] link is up
  • [Interface name] Interface link status changed to down
  • [Interface name] Interface link status changed to up
  • System back up succeeded
  • Full state synchronization from master [serial number] to backup master [serial number] completed successfully

Screen shot of log messages for a FireCluster reboot

Related Topics

About FireCluster in WatchGuard Cloud