Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sending Logs to IView Server

Under "System Services" is Log Settings.

What are the correct setting to send log to our IVEW 2 server.

My iview server appears to be only getting part of the logs.

What I have.

Port:514

Facility: DAEMON

Severity: Debug

Format: Device Standard Format.



This thread was automatically locked due to age.
Parents
  • Hi Navar ,

    As per Luk , check the KB article. Also make sure your Iview server is up and running 24/7 . If you system is off for a day or two you would not retrieve the logs for that day . Also you may check the communication of the Iview and XG by checking on console.

    console>tcpdump 'port 514

  • After working with support for almost two hours all of the settings on both the XG and the Iview look correct.

    We found that there is a 2 hour lag between XG logs and Iview logs.

    Also Iview will only show a detailed report.  The summary report is blank.

    Also Iview under the Main Dashboard only shows "Blocked Traffic".  "Allowed Traffic" is blank and doesn't list the XG device.

Reply
  • After working with support for almost two hours all of the settings on both the XG and the Iview look correct.

    We found that there is a 2 hour lag between XG logs and Iview logs.

    Also Iview will only show a detailed report.  The summary report is blank.

    Also Iview under the Main Dashboard only shows "Blocked Traffic".  "Allowed Traffic" is blank and doesn't list the XG device.

Children