Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hugo_vd_Kooij
MVP Gold
MVP Gold

How to get a smarter log?

Here is my puzzle I have with a customer.

We incresed security by switching IPS from detect to prevent.

We noticed a lot of DETEC log entries and were going over the steps to make sure we didn't miss anything. And everything is as it should be.

Then I did track the specific source and reviewed the logs and found the reason.

If another blade (FW or VPN) drops the packet/connection then IPS only logs a DETECT as another blade did the blocking action. So now I would very much like to see if there is a simple way to get the details from the DETECT log entry and then open a second log tab with a filter based on the Source IP and destination IP of the DETECT log line I am investigating.

Anyone with a suggestion in this regard?

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
1 Reply
elbergfeldt
Participant

Hi! 

Not sure if there is an easy way of doing this in one click, but you can undock the logs tab (top right button) and have two windows open at the same time side by side while you conduct your investigation 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events