Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
intaq
Explorer

FilterConfiguration.xml | Log Filtering is not working after upgrade

Hello !

We had configured in the FilterConfiguration.xml file a series of filters to not send traffic events in order not to saturate the SIEM, commenting some lines #. This worked for a while, recently the SMS was updated and this stopped working. The file was not altered, it remains the same as before the update

I have tried restarting with cp_log_export restart and installed DB again in case this could affect but it continues to send traffic logs. The file has not been modified after these tests either.

The version is R81.10 JHF 139

Any ideas or something similar that may have occurred to you? 

Thanks!

0 Kudos
1 Reply
Alex-
Leader Leader
Leader

We have a similar issue with TLS certificates after each jumbo.

 

Restarting the Log Exporter isn't enough, we need to actually delete the instance and recreate it, then everything works again.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events