I have a requirement where i need to forward logs from my R80.40 Gateway Cluster to Datadog.. this is being done by forwarding syslogs to an intermediate syslog server and from there syslogs are being forwarded to Datadog.
i tried doing this via log exporter but in datadog console and syslog server i only saw gateway name and message id .. no other infor was available so i went with conventional syslog integration
Post that ..In datadog i can see traffic logs in the form of traffic being allowed along with NAT translations but i cannot see any audit logs nor any traffic drop logs which are through the implicit deny rule.
My queries here are.
1) Does simple syslog integration with Mgmt server include audit logs ? does syslogs include auditlog info as well ?
2) Is log exporter the only way to forward audit log information ?
3) any reason i cannot see drop logs there ?