In monitoring the XG syslog we see individual syslog events for each subnet mapped by the Connect policy. This means 8+ syslog events for every single user who connects with Connect via IPSec. Is there a specific syslog setting we can look for or use to make sure only one logon event is registered? The XG logs do not work well with our SIEM by default like our other firewall brands and their VPNs.
This thread was automatically locked due to age.