---
title: "Security logs"
canonical: "https://docs.aryaka.com/space/KNOW/41943118/Security%20logs"
format: markdown
---
The Security Logs page displays network events that required a security action to be taken as a time series graph and as a table. These events include establishing flows, HTTP requests, security rule enforcement, and so on. To view security logs If it is not already open, navigate to the Security Logs page: Log in to MyAryaka. The Home page appears. Click  Insights  >  Log Explorer  in the left navigation pane. The Log Explorer page appears. Click  Explore Logs  in the Security Logs tile. The Security Logs page appears. Click the  Scope  drop-down list, then select one of the following options whose security log you want to view: Global—Displays data for all sites and private access nodes.  All Sites—Displays data for all sites.   All Nodes—Displays data for all private access nodes. A specific site—Displays data for only the selected site. A specific node—Displays data for only the selected private access node. The components of the Security Logs page are described in the following sections. Filter The filter allows you to view security logs that meet selected criteria or that occurred during a defined time period. You can select whether to use the Basic or Aryaka Query Language (AQL) filter to add filter criteria. The Time drop-down list allows you to select one of the following time periods to view security logs for: Last 1 Hour Last 4 Hours Last 8 Hours Last 24 Hours Last 7 Days Last Day Last Week Custom Range After adding filter criteria, click  Apply  to activate the selected filter. To remove selected filters, click  Clear All . When you have created your filter, you can click  Save  to save the current filter criteria. You can then use the filter drop-down list to select a saved filter. Basic With the Basic filter, you can click the  Add  icon to filter the logs by specific criteria, for example, source IP, user, or a security rule action. When entering values, use the drop-down list to specify whether to search for logs that match the value (=), logs that do not match the value (!=), or, for some criteria, logs that have a partial match (~) for the value. When entering IP addresses, CIDR notation is supported. There are three types of available filter criteria: criteria that allow you to select multiple entires from a searchable drop-down list, criteria that allow you to enter multiple alphanumeric strings that are treated as OR conditionals (note that you must click  Update  to include entered values in the filter), and criteria that allow you to enter a range of values. AQL With the Aryaka Query Language (AQL) filter, you can manually enter the fields, conditions, and associated values you want to filter for. For example, to view only logs for outgoing traffic that was denied, enter  DIRECTION = 'Outgoing' AND ACTION = 'Deny'  in the AQL field. The AQL filter allows you to use OR conditionals for different filter criteria, which is not possible with the Basic filter.   Statistics The Statistics pane displays a time series graph and drop-down panes that provide details on the displayed security logs. If you want to hide the Statistics pane, click the  Collapse  icon.  The time series graph displays the total number of flows, the number of permitted flows, and the number of denied flows for the selected time period and filter criteria. The graph includes the following functionality: Hover over the graph to display the value of each statistic plotted on the graph at the corresponding time.  Click a category in the legend to hide or show the corresponding line in the graph. At least one category must remain selected. Hidden categories are represented by a white outlined box and displayed categories use a solid color. Click, drag, and release to select a smaller window of time to display. This custom time selection now applies to all graphs on MyAryaka. After you select a custom time period, it is retained until you click the  Reset  icon in the Filter pane. Expand   the following drop-down panes to view statistics for the category: Actions Clients Users Domain Categories URL Categories Domains Domain Reputation Score URL Reputation Score Destination IPs Destination Ports Uncommon Destination Ports Discovered Applications Source Networks Destination Networks QoS Each drop-down pane displays the category’s top values for the selected security logs. The following graphic shows the Clients drop-down pane expanded to display the top clients for the selected security logs: You can use the values displayed in the drop-down panes to create a filter for your security logs. For example, to view security logs for your organization's top five clients, select the first five clients (shown in the following graphic), then click  Apply  in the filter pane to refresh the Security Logs page with the logs that match your selection. Security Logs table The Security Logs table displays a row for each network event that occurred during the selected time period. The table displays the following columns by default: Event Time Site Name (note that this column always displays Site Name even if the Scope field is set to a private access node or a combination of sites and nodes) Source IP User Destination IP Destination Port Protocol Action Domain Auto-Discovered App Click the  Gear  icon to select which columns are displayed in the Security Logs table. You can also click and drag the column names to reorder the columns as needed.  Click the  Download  icon to download a CSV file of the security logs to your local computer. The CSV file contains a column for each field of the security logs table, regardless of which fields you have currently displayed.  You can hover over an individual cell in the table to display the Options icon. Click the  Options  icon, then click  Add to Filter  to create a filter with the corresponding criteria and value. Note that you must then click  Apply  to activate the filter.  Click a security log to display the Log Preview pane, which provides event details and the security rule verdict and action that was applied to the traffic. The Log Preview pane includes the following elements:  Share icon—Copies the MyAryaka URL for the selected security log so that you can share it as needed. View Details—Displays the  Security Log Details  page, which provides additional details about the event. Collapse icon—Hides the Log Preview pane.  Related topics Security Monitor SD-WAN View security log details