Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

The reports contain no records

Maybe I am doing something wrong, but I go to Reports, Traffic Dashboard, View All and select a date range of last couple of days, but the report does not contain any data. There is nothing under any of the headings. UTM9 used to provide very nice report. How to generate UTM9 kind of report in XG?

Thanks,

Arun



This thread was automatically locked due to age.
  • Arun,

    are the log enabled? go to system services > log settings > local (flag all checkboxes).

    Regards

  • There can be several reasons for this, some of them being (non-exhaustive list) :

     

    - Logging/Reporting service is Dead (You can check on Control Center or System Services)

    - Disk is full (Login via CLI -> 4. Console -> system diagnostics show disk)

    - You have applied Web Filter policy as 'None'. Make sure that it is at least 'Allow All' for logs to generate

     

    As you mentioned you are looking for reports for the last couple of days. Try going back a few months and check if you can see any reports.

  • The Local box is unchecked. I have checked this box, but after I hit Apply, the box becomes unchecked again.

    Thanks,

    Arun

  • I do not see a logging/reporting service under System Services. These are the only ones that I see:

    Anti-Spam
    Anti-Spam Center Connectivity
    Anti-virus
    Authentication
    DNS Server
    IPS
    Web Proxy
    WAF
    DHCP Server
    DHCPv6 Server
    Router Advertisement Service
    Hotspot

    The disk is not full. This is what the command shows:

    configuration 16%
    content        3%
    report         2%

     

    I do have Web Policy as None in every firewall rule. I do not use Web Policy at all. Is it required to have it Allow All? I will test by changing it.

     

    I did try going back weeks, but there is nothing. I just want to see a basic report like traffic processed in GB, top data consuming hosts, dropped packets etc.

     

    Thanks,

    Arun

  • If web profile is not allow all, you will not get web categories been used. Network traffic should however be available if log settings checkboxes are configured. What appliance are you using?

    Thanks

  • I am not using an appliance. XG is installed on a VM. Log setting checkboxes are configured as below but nothing is shown in the traffic dashboard.

     

     

    Thanks...

  • Arun,

    check from console that reporting is enabled:

    show on-box-reports

    Local reporting is on

    Regards

  • Yes, local reporting is on. I did configure one firewall rule with Web Policy: Allow All. Now I see some data in the reports. Is this all I can get?

    Thanks much for your help...

     

  • In that same rule try setting Application Filter as Allow All and enable Log Firewall Traffic at bottom of Firewall Rule.

    Regardless of these settings you should be able to see other  reports like Network Attacks (If IPS Policy is applied), other things on Traffic / Security Dashboard etc. Are you able to see Reports  -> Compliance -> Events -> Admin Events ?

  • Yes, I had set Application Filter also to Allow All when I was setting the web policy to allow all. I will test with Log Firewall Traffic.

    I do see some information in Admin Events, like it has recorded all the events when I made changes to Firewall Rules for Web Policy and Application Policy. I do not have IPS enabled. I will test enabling IPS.

     

    Thanks,

    Arun