This is what you should see on the gateway that is centrally managed:
GW8010> fw log | more
GW8010> expert
Enter expert password:
Warning! All configurations should be done through clish
You are in expert mode now.
[Expert@GW8010:0]# fw log | more
[Expert@GW8010:0]#
and this is what you should see on the management server where logs are being forwarded to:
login as: admin
This system is for authorized use only.
admin@192.168.7.30's password:
Last login: Mon Sep 24 09:22:24 2018 from 192.168.7.148
SMS8010> fw log | more
Date: Sep 24, 2018
0:00:00 5 N/A 1 ctl SMS8010 > daemon LogId: <max_null>; ContextNum: <max_null>; OriginSicName: cn=cp_mgmt,o=SMS8010..bhska4; OriginSicName: cn=cp_mgmt,o=SMS8010..bhska4; HighLevelLogKey: 18446744073709551615; log_sys_message: Log file has been switched to: 2018-09-24_000000.log; ProductName: VPN-1 & FireWall-1; ProductFamily: Network;
Date: Sep 23, 2018
23:58:04 5 N/A 11 accept GW8010 < eth2 LogId: 0; ContextNum: <max_null>; OriginSicName: CN=GW8010,O=SMS8010..bhska4; OriginSicName: CN=GW8010,O=SMS8010..bhska4; HighLevelLogKey: 18446744073709551615; inzone: Local; outzone: Internal; service_id: domain-udp; src: GW8010; dst: DC16; proto: udp; user: ; src_user_name: ; src_machine_name: ; src_user_dn: ; snid: ; dst_user_name: ; dst_machine_name: dc16@higherintelligence.com; dst_user_dn: ; UP_match_table: TABLE_START; ROW_START: 0; match_id: 4; layer_uuid: 1d365ba8-9fb0-4279-8f26-3b0842cccb54; layer_name: GW8010-Composite-Demo Network; rule_uid: 3d2f9eb5-f989-4f61-aaf6-c2d336555e0e; rule_name: For Nessus Scans; action: 2; parent_rule: 0; ROW_END: 0; UP_match_table: TABLE_END; ProductName: VPN-1 & FireWall-1; svc: domain-udp; sport_svc: 49371; ProductFamily: Network;