Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Pedro_Espindola
Advisor
Jump to solution

What happened to loguid/UUid in syslog of new Quantum Spark?

What happened to loguid/UUid in syslog of new Quantum Spark?

In R77.20.87 for 700/1400 appliances there was the UUid field which could be used to correlate the delta logs.

In the new versions there is no loguid or equivalent field. This means it is impossible to correlate a lot of information, such as the office mode IP of a user that connected to Remote Access VPN.

This was a huge step backwards. The details of the logs have improved, but without this field to allow correlation the logs are useless.

0 Kudos
1 Solution

Accepted Solutions
Pedro_Espindola
Advisor

I received a solution from TAC a few days ago.

This solution does not survive upgrades and they still haven't confirmed if it will be made default in the next builds.

Here is the procedure to enable this field:

Access vis SSH to /opt/fw1/conf/log_fields.C

Search for :field_name (uuid)

Change:

:application_display_mode (none)

        :application_name (FWLog)

To:

:application_display_mode (own_column)

        :application_name (FWLog)

Then run sfwd_restart

View solution in original post

5 Replies
PhoneBoy
Admin
Admin

What code version?
@Amir_Ayalon are you familiar with this issue?

0 Kudos
Pedro_Espindola
Advisor

R81.10.XX

I still haven't tested the newest build from last month, but all the previous ones had this ussue.

0 Kudos
Pedro_Espindola
Advisor

R81.10.07 is also affected.

Very frustrating, because log rate to SMP is limited to 10000/hour, which is very low, leaving huge gaps in logs.

Also retention is less than a month.

Plus I can't export from SMP to a SIEM.

So exporting syslog was the best way to have a better log retention, which is is a MUST even for small organizations today due to new regulations.

Pedro_Espindola
Advisor

I received a solution from TAC a few days ago.

This solution does not survive upgrades and they still haven't confirmed if it will be made default in the next builds.

Here is the procedure to enable this field:

Access vis SSH to /opt/fw1/conf/log_fields.C

Search for :field_name (uuid)

Change:

:application_display_mode (none)

        :application_name (FWLog)

To:

:application_display_mode (own_column)

        :application_name (FWLog)

Then run sfwd_restart

Tom_Hinoue
Advisor
Advisor

Thanks for sharing! good to know 🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events