Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MasterChief117
Contributor
Jump to solution

No Connection Type Data in Reports

Dear All

 

I wanted to create a report for access rule drops for a specific IP or a specific services and noticed that the reports would come empty, after investigating further I noticed that no log with type connection is taken into account. Is there any way to use these data in a report?

 

Kind Regards

0 Kudos
2 Solutions

Accepted Solutions
MasterChief117
Contributor

Helo amirse thanks for your reply

 

I am attaching the tracl option as it is right now. Only per connection is ticked, are you saying that if I tick per session as well it will work?

snip.PNG

View solution in original post

0 Kudos
Dror_Aharony
Employee Alumnus
Employee Alumnus

Yes.

SmartEvent only indexes 'Session' logs.

That's the way to log FW session logs & have them seen on the SmartEvent Views/Reports.

 

View solution in original post

0 Kudos
3 Replies
Amir_Senn
Employee
Employee

If you go to the rules that you want to see in the report and change track option to be both sessions and connection you'll see the relevant information.

If you need even more information you can also go to non-firewall rules and enable firewall session. IMO it might not contribute to much though.

Kind regards, Amir Senn
0 Kudos
MasterChief117
Contributor

Helo amirse thanks for your reply

 

I am attaching the tracl option as it is right now. Only per connection is ticked, are you saying that if I tick per session as well it will work?

snip.PNG

0 Kudos
Dror_Aharony
Employee Alumnus
Employee Alumnus

Yes.

SmartEvent only indexes 'Session' logs.

That's the way to log FW session logs & have them seen on the SmartEvent Views/Reports.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events