Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Nickel

Export log from ChP EndPoint management to central ChP management by Log Exporter

Hi,

Customer have two MultiDomainManagementServers to control all ChP gateways, this two MDSs are connected with SmartEvent. He also have one SingleDomainManagement just for EndPoint security. 

I would like to start forwarding all logs from SDM to MDM (specific CMA). Something similar is described in sk35288, but it's not the same and it's not very elegant way to do it. I would prefer to use Log Exporter for it but TAC told me, that this is not supported solution. To be honest I don't understand why, management already can receive syslog so it's all about sending it in right format (should be easy to implement it to Log Exporter). 

 

I would like to know, if anyone of you have similar problem as I have and if so how you solved it.

 

 

0 Kudos
3 Replies
Highlighted
Admin
Admin

Re: Export log from ChP EndPoint management to central ChP management by Log Exporter

Why do you prefer to use Log Exporter?
0 Kudos
Highlighted
Nickel

Re: Export log from ChP EndPoint management to central ChP management by Log Exporter

From mine point of view, Log Exporter is extra safe (not necessary to make any hacks on any device) and it allows me to store all logs on one place (MDS appliances have lot of space compere to EndPoint management server). 

Solution from sk35288 is not look very safe ("This procedure must be performed during a maintenance window.", "Before making any changes, take a complete backup / snapshot of each involved machine.") and it in R80.10 environment it requires extra hotfix. Also it allows only SE to work with logs of EPM not transfer logs to one place (MDS-CMA).

0 Kudos
Highlighted
Admin
Admin

Re: Export log from ChP EndPoint management to central ChP management by Log Exporter

Reading the SK, the "hacks" are about establishing SIC with the other log server and making the necessary configuration changes to allow logs to be pulled via LEA.
The "maintenance window" warning is more about administrators working on the system at the same time versus impacting production traffic flowing through the Security Gateways.
Also, it should pull all the logs across for use with SmartView in R80.x, but maybe I'm wrong about that.
0 Kudos