Blew away our old Smartevent server yesterday and built a new one running R80.10. Fresh install.
Running a separate management and Smartevent server
Did the SIC, licensing, install database and let it do it's thing.
I seem to be getting logs but the accept logs stopped after a day. I had run some commands to import the previous months logs. Changed the $INDEXERDIR/log_indexer_custom_settings.conf to that it would index 28 days.
Today I wiped it and tried again. Figured I messed something up on it which caused the stoppage.
Setup went fine with no errors. Hooked up to MGMT server and logs are importing. Problem is that only drop and detect logs are entered again. No allowed logs.
Any idea on how to get the other logs to show up?