Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hrvoje_Brlek
Contributor

Identity Collector - number of events

Jump to solution

Hi,

I am setting up an Identity Collector in our CP environment. I have one question regarding the number of events. In the Identity Collector dashboard I can see the number of events being sent, and through the Gateway CLI we can see also the number of events, but these two numbers do not correlate with each other. Is this an expected behavior?

I'm sending the examples below.

Identity Collector:

Untitled2.png

Untitled1.png

Gateway CLI:

Izrezak.JPG

0 Kudos
Reply
1 Solution

Accepted Solutions
Royi_Priov
Employee
Employee

Hi @Hrvoje_Brlek 

have you enabled the monitoring feature on IDC side? (check "Monitoring capability" section under sk108235)

Thanks,
Royi Priov
Group manager, Identity Awareness R&D

View solution in original post

0 Kudos
Reply
7 Replies
PhoneBoy
Admin
Admin
0 Kudos
Reply
Royi_Priov
Employee
Employee

Hi @Hrvoje_Brlek,

I don't remember the calculation behind "pdp conn idc" event counter, but probably there is a logic to unify the events for same user&IP (while the UI for sure doesn't unify them).

To see the same output as the IDC UI, you can use "pdp idc status"  (R80.30 and above) or "cpstat identityServer -f idc"

Thanks,
Royi Priov
Group manager, Identity Awareness R&D
0 Kudos
Reply
Hrvoje_Brlek
Contributor

Hi,

When I run those commands, this is the output I get:

ic-CP.jpg

The same output is on a Gateway running 80.40 JHF T83 and on 80.30 JHF T219.

Am I doing something wrong?

There is no connectivity issues between Identity Collector and the Gateways (both VSX), nor are there any firewalls on the way. Identity collector version is the latest one from CP, it has configured six DCs, with all of them generating events visible through IC dashboard.

0 Kudos
Reply
G_W_Albrecht
Champion
Champion

Why not have TAC resolve this ? Does not look healthy...

0 Kudos
Reply
Hrvoje_Brlek
Contributor

Already have a few TAC cases open. Would really like not to have to open a TAC case for every minor change or implementation in a Check Point environment. 😐

But, if necessary will do so...

0 Kudos
Reply
Royi_Priov
Employee
Employee

Hi @Hrvoje_Brlek 

have you enabled the monitoring feature on IDC side? (check "Monitoring capability" section under sk108235)

Thanks,
Royi Priov
Group manager, Identity Awareness R&D

View solution in original post

0 Kudos
Reply
Hrvoje_Brlek
Contributor

Works like a charm, thank you very much 😊

Grateful that no TAC was necessary 😉