Log Overview
These screens allow you to determine the categories of events and/or alerts that the Zyxel Device logs and then display these logs or have the Zyxel Device send them to an administrator (through email) or to a syslog server.
What You Can Do in this Chapter
Use the System Log screen to see the system logs (System Log).
Use the Security Log screen to see the security-related logs for the categories that you select (Security Log).
What You Need To Know
The following terms and concepts may help as you read this chapter.
Alerts and Logs
An alert is a type of log that warrants more serious attention. They include system errors, attacks (access control) and attempted access to blocked web sites. Some categories such as System Errors consist of both logs and alerts. You may differentiate them by their color in the View Log screen. Alerts display in red and logs display in black.
Syslog Overview
The syslog protocol allows devices to send event notification messages across an IP network to syslog servers that collect the event messages. A syslog-enabled device can generate a syslog message and send it to a syslog server.
Syslog is defined in RFC 3164. The RFC defines the packet format, content and system log related information of syslog messages. Each syslog message has a facility and severity level. The syslog facility identifies a file in the syslog server. Refer to the documentation of your syslog program for details. The following table describes the syslog severity levels.
Syslog Severity Levels 
Emergency: The system is unusable.
Alert: Action must be taken immediately.
Critical: The system condition is critical.
Error: There is an error condition on the system.
Warning: There is a warning condition on the system.
Notice: There is a normal but significant condition on the system.
Informational: The syslog contains an informational message.
Debugging: The message is intended for debug-level purposes.