Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Andrey_Ganichev
Participant
Participant

Logs from TE SG on TE Appliance managed by a different MGMT

Hello,

I have the question about TE logs. There is a such configuration (sk102309 section 10) : TE Appliance R77.30 JHF Take 338 engine 57.990004002 is managed MGMT-TE R80.20. GWS that send files for emulation to TE Appliance are manager anothers MGMT. In SmartLog on MGMT-TE R80.20 I don't see Threat Emulation logs. Is it by design or something wrong in a configuration?

tecli s s
General Information:
--------------------
Scanned files: 5 264

Files destined for Local Emulation:
-----------------------------------
Scanned files locally: 5 264

3 Replies
PhoneBoy
Admin
Admin

I assume the logs would go to the log server it is configured to go to (i.e. by the other management).

0 Kudos
Andrey_Ganichev
Participant
Participant

On the other mamangement (manages the GW) I see TE logs.
tecli advanced remote emulator logs enable on GW must enable the logs on TE MGMT I think..
It seems I see only logs with malisious if detected.

0 Kudos
Thomas_Werner
Employee Alumnus
Employee Alumnus

In your case by default if using two dedicated Mgmts logs should be created on both log servers.

If you have a distributed setup with one Mgmt (so GW and SB appliance in one Mgmt) you would only get one log from the GW.

Regards Thomas

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events