- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Log export for virtual system on VSX
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log export for virtual system on VSX
Dear All,
One of our customers would like to receive their firewalls logs on their SIEM (Splunk).
They are currently using a shared firewall and we want to ensure they only get their own logs. We are planning to move them to a dedicated virtual firewall on VSX.
Could we send them logs directly from their virtual system in SMS (potentially using Log Exporter and filter-origin-in) or would it be better to use MDS and create a separate domain for them?
We are currently running R80.20, take 118.
Thanks for your help!
Best regards,
Harry
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @net-harry,
I think it is both possible:
1) Use a MDS and create a second CMA or log server.
2) Use the filter configuration file. Is located under each target folder: $EXPORTERDIR/targets/<target-name>/conf/FilterConfiguration.xml. The filtering feature allows to decide which logs will be exported based on values on the raw log. More read here sk122323.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @net-harry,
I think it is both possible:
1) Use a MDS and create a second CMA or log server.
2) Use the filter configuration file. Is located under each target folder: $EXPORTERDIR/targets/<target-name>/conf/FilterConfiguration.xml. The filtering feature allows to decide which logs will be exported based on values on the raw log. More read here sk122323.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using a seperate CMA per customer with MDS gives alot more flexibility.
If possible i would go for that soultion all days of the week 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@HeikoAnkenbrand and @Magnus-Holmberg Thanks for your help!
I will try and check which solution would be most suitable for us.
Best regards,
Harry
