- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Updatable Objects - certain logs not indexed
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Updatable Objects - certain logs not indexed
Has anyone noticed certain logs not indexed by SmartLog? I tested with R80.20 GA (take 33) and a partner was using R80.20 M2. In SmartLog we didn't see any logs to Countries or MS services, but I did see logs destined for AWS IP addresses. However, when you open SmartView Tracker, you can see entries with the raw data.
I was using www[.]cnblogs[.]com for a destination in China.
The specific use case was to move away from Geo-Protect as many resources are located in other countries these days. Using Updatable Objects should allow for a better white-listing of exceptions... but they need to see the logs should any future exception come up.
Many thanks for a sanity check!
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We've had a few discussions about things not getting indexed in SmartLog, though I wasn't aware that anything related to Updatable Objects wasn't showing up.
It's probably worth a TAC ticket as the countries are supposed to show up.
It's probably worth a TAC ticket as the countries are supposed to show up.
