Hi Mates!!!!
Hope you all doing well.
I have a few questions regarding a feature introduced in R82.10, specifically the Log Generation Mode, and in particular the Aggregate Mode:
- Generates logs per session and combines multiple connection logs into a single log. Aggregate mode significantly reduces log volume and cloud storage costs.
From my understanding, this setting is applied globally across the policy packages managed by the Management Server. Also, it seems that it effectively changes the logging behavior from per-connection to per-session.
Could you please confirm if this understanding is correct?
Additionally, I would like to clarify the following:
- If we switch to Aggregate Mode, does it impact all policies in terms of logging behavior (i.e., converting all logs to session-based)?
- In case we decide to revert back to Standard Mode (for example, if we lose visibility on certain logs such as NAT), will the previous logging behavior be automatically restored as it was before?
Thank you in advance for your support.