Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Support_Effia
Participant

cp_log_export syslog config Filter FilterConfiguration.xml

Hi,

I want to use the file FilterConfiguration.xml and only export log from only one GW.

For that I want to use the filed name origin_sic_name

My file is look like that:

<filters>
        <filterGroup operator="and">
                <field name="action" operator="and">
                </field>
                <field name="origin" operator="and">
                </field>
                <field name="product" operator="and">
                </field>
        </filterGroup>
        <filterGroup operator="and">
                <filed name="origin_sic_name" operator="and">
                        <value operation="eq">CN=NAMEOFFW</value>
                </filed>
        </filterGroup>
</filters>

 

But it do not work and export all logs from our smartLog...

Can you help me please?

Regards.

2 Replies
PhoneBoy
Admin
Admin

I'm guessing the SIC name will be the full DN as listed in the SIC status of the relevant gateway object.
Why use that versus origin with the just the simple gateway object name?

genisis__
Leader Leader
Leader

I've done something like this where I exported only ThreatPrevention logs for specific gateways.

cp_log_export set name <LogServer> domain-server <DMS1> filter-blade-in "TP" filter-origin-in "a.a.a.a,b.b.b.b,c.c.c.c"
Note: The above adds entries into $EXPORTERDIR/targets/<name>/conf/FilterConfiguration.xml

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events