Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend
Jump to solution

Dedicated smart event server logging behavior

Hey guys,

I wanted to bring this up, as Im not 100% sure if this is indeed an expected behavior and if people are aware of it or not. So, my impression was always that say if you have dedicated SE server, you have to add it to logging options on the gateway(s) object in order for logs to sent to it, but that is supposedly NOT the case.

Reason I say that is because my colleague and I had call with TAC and guy was excellent, he did help us with a different SE server issue, but even he said customer's smart event was not used for logging or getting any logs, which we discovered later was actually not true, as we saw bunch of logs sent to it when we logged in via smart console.

Now, to verify this behavior, I also tested in my own lab, where my mgmt is 172.16.10.252 and se server is 172.16.10.244. Though I dont have smart event object added anywhere for logging options on cluster or single gw, I can see bunch of logs on se server when I open separate smart console instance.

So, my question is...is this NORMAL (expected) behavior?

I also attached screenshots showing what I described.

Best and thanks as always for the help!

Andy

 

 

 

0 Kudos
1 Solution

Accepted Solutions
Lesley
Leader Leader
Leader

I think it is normal because smart event needs logs to do its job. And will get it from log server. For performance it is better to have 1 log server and 1 event server. If event has no access to logs it will have no data to work with. Under my gateways I always put the log servers as log server (or other name for it: smart mgmt)

-------
If you like this post please give a thumbs up(kudo)! 🙂

View solution in original post

5 Replies
Lesley
Leader Leader
Leader

I think it is normal because smart event needs logs to do its job. And will get it from log server. For performance it is better to have 1 log server and 1 event server. If event has no access to logs it will have no data to work with. Under my gateways I always put the log servers as log server (or other name for it: smart mgmt)

-------
If you like this post please give a thumbs up(kudo)! 🙂
the_rock
Legend
Legend

Thanks @Lesley ! Yes, I know most people do the same, but it just caught me off guard, as I always thought smart event needs to be in that list to be receiving logs, but supposedly not.

Anyway, appreciate the confirmation 🙂

Andy

0 Kudos
Amir_Senn
Employee
Employee

SmartEvent could also be a log server. This is a matter of distributing resources if needed.

If SmartEvent is not the log server it will have better performance than doing both, and considering that it can read logs from multiple log servers it very much depends on logging rate.

Kind regards, Amir Senn
the_rock
Legend
Legend

Hey @Amir_Senn 

So, just co confirm 100%, my assumption was indeed correct then that say even if you do NOT add SE object in logging tab for the gateway, it would still be getting logs by default?

Andy

0 Kudos
Amir_Senn
Employee
Employee

Defined in SmartEvent GUI (Analyzer). When deploying a new SmartEvent server, by default it should apply all log servers currently connected to the environment. If you add new ones you'll need to define them.

Kind regards, Amir Senn
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events