Hey,
I deployed Anti-Virus and Anti-Bot for a customer, for now without HTTPS inspection and just in detect mode for testing. The customer is expecting some log reports showing what's going on, but all my logs look as on the attached screenshots. I opened a TAC case but they just told me that my config is correct and they have no idea, but I need to test a few URL's and provide the timestamps for this testing. Getting the customer to do these tests is not easy so I thought I'll ask in the meanwhile here, maybe someone had a similar issue?
Result is the same whether I use SmartConsole or SmartView. Doesn't show anything more in the Corelated events report either.
IPS logs look fine, it's just the anti-bot/virus blades acting up.