Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
asdfn
Explorer

Smart-1 Console - Forward to SIEM Log Size Provision

Hi all,

 

I am using the "Forward to SIEM" feature from Smart-1 Cloud console to the SIEM. Before establishing the connection, I checked the Daily logs in Smart-1 Cloud console under Settings -> General, which should be around 15GB daily. However, once I established the connection, the log size was higher than expected. It generated around 2GB of logs in just 5 minutes of connection.

I'd like to know if the Smart-1 Console sends stored logs like past 1- or 2-days logs when the Forward to SIEM feature is successfully connected?

Thank you for any assistance

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

On the management server (also relevant for Smart-1 Cloud), new log files are created every 24 hours at a fixed time as well as anytime the current log file gets to 2GB.
Log Exporter (which Smart-1 Cloud uses) only works with the current log file.
Therefore, it seems reasonable that we'd send the contents of the current log file once activated, meaning you'll get data from up to the last 24 hours.

0 Kudos
Upcoming Events

    CheckMates Events