Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
net-harry
Collaborator

Log export for virtual system on VSX

Jump to solution

Dear All,

One of our customers would like to receive their firewalls logs on their SIEM (Splunk).

They are currently using a shared firewall and we want to ensure they only get their own logs. We are planning to move them to a dedicated virtual firewall on VSX.

Could we send them logs directly from their virtual system in SMS (potentially using Log Exporter and filter-origin-in) or would it be better to use MDS and create a separate domain for them?

We are currently running R80.20, take 118.

Thanks for your help!

Best regards,

Harry

1 Solution

Accepted Solutions
HeikoAnkenbrand
Champion
Champion

Hi @net-harry,

I think it is both possible:

1) Use a MDS and create a second CMA or log server.
2) Use the filter configuration file. Is located under each target folder: $EXPORTERDIR/targets/<target-name>/conf/FilterConfiguration.xml. The filtering feature allows to decide which logs will be exported based on values on the raw log. More read here sk122323.

View solution in original post

3 Replies
HeikoAnkenbrand
Champion
Champion

Hi @net-harry,

I think it is both possible:

1) Use a MDS and create a second CMA or log server.
2) Use the filter configuration file. Is located under each target folder: $EXPORTERDIR/targets/<target-name>/conf/FilterConfiguration.xml. The filtering feature allows to decide which logs will be exported based on values on the raw log. More read here sk122323.

View solution in original post

Magnus-Holmberg
Advisor

Using a seperate CMA per customer with MDS gives alot more flexibility.
If possible i would go for that soultion all days of the week 🙂

https://www.youtube.com/c/MagnusHolmberg-NetSec
net-harry
Collaborator

@HeikoAnkenbrand  and @Magnus-Holmberg  Thanks for your help!

I will try and check which solution would be most suitable for us.

Best regards,

Harry

0 Kudos