- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Export log from ChP EndPoint management to central...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Export log from ChP EndPoint management to central ChP management by Log Exporter
Hi,
Customer have two MultiDomainManagementServers to control all ChP gateways, this two MDSs are connected with SmartEvent. He also have one SingleDomainManagement just for EndPoint security.
I would like to start forwarding all logs from SDM to MDM (specific CMA). Something similar is described in sk35288, but it's not the same and it's not very elegant way to do it. I would prefer to use Log Exporter for it but TAC told me, that this is not supported solution. To be honest I don't understand why, management already can receive syslog so it's all about sending it in right format (should be easy to implement it to Log Exporter).
I would like to know, if anyone of you have similar problem as I have and if so how you solved it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From mine point of view, Log Exporter is extra safe (not necessary to make any hacks on any device) and it allows me to store all logs on one place (MDS appliances have lot of space compere to EndPoint management server).
Solution from sk35288 is not look very safe ("This procedure must be performed during a maintenance window.", "Before making any changes, take a complete backup / snapshot of each involved machine.") and it in R80.10 environment it requires extra hotfix. Also it allows only SE to work with logs of EPM not transfer logs to one place (MDS-CMA).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The "maintenance window" warning is more about administrators working on the system at the same time versus impacting production traffic flowing through the Security Gateways.
Also, it should pull all the logs across for use with SmartView in R80.x, but maybe I'm wrong about that.
