Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Participant

No Connection Type Data in Reports

Jump to solution

Dear All

 

I wanted to create a report for access rule drops for a specific IP or a specific services and noticed that the reports would come empty, after investigating further I noticed that no log with type connection is taken into account. Is there any way to use these data in a report?

 

Kind Regards

0 Kudos
Reply
2 Solutions

Accepted Solutions
Highlighted
Participant

Helo amirse thanks for your reply

 

I am attaching the tracl option as it is right now. Only per connection is ticked, are you saying that if I tick per session as well it will work?

snip.PNG

View solution in original post

0 Kudos
Reply
Highlighted
Employee++
Employee++

Yes.

SmartEvent only indexes 'Session' logs.

That's the way to log FW session logs & have them seen on the SmartEvent Views/Reports.

 

View solution in original post

0 Kudos
Reply
3 Replies
Highlighted
Employee+
Employee+

If you go to the rules that you want to see in the report and change track option to be both sessions and connection you'll see the relevant information.

If you need even more information you can also go to non-firewall rules and enable firewall session. IMO it might not contribute to much though.

Kind regards, Amir Senn
0 Kudos
Reply
Highlighted
Participant

Helo amirse thanks for your reply

 

I am attaching the tracl option as it is right now. Only per connection is ticked, are you saying that if I tick per session as well it will work?

snip.PNG

View solution in original post

0 Kudos
Reply
Highlighted
Employee++
Employee++

Yes.

SmartEvent only indexes 'Session' logs.

That's the way to log FW session logs & have them seen on the SmartEvent Views/Reports.

 

View solution in original post

0 Kudos
Reply