Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cathychan
Participant

smartview monitor and smartview logs didnt match

Hello Guys, I have a question about our monitoring tools, on smartview I am seeing a huge spike on SRC and DEST. however, when I check on smartview logs I didnt see the logs for it

 

example

Smartview monitor shows 60Gbps of traffic spike for SRC A and DEST B.

when I review the logs on smartview logs this connection didnt show up.

Note: we have a specific rule that allows the connection.

Any reasons you know why?

 

 

thank you!

0 Kudos
7 Replies
_Val_
Admin
Admin

How did you search?

0 Kudos
_Val_
Admin
Admin

It seems to me, you are missing a font or two, so they do not render.

0 Kudos
cathychan
Participant

thank you Val for response, can you share what do you mean by Font 😄 Im sorry I am new.. If you mean filter.. what I did is 

origin: FWCluster

Source: SOURCEIP

port: 2049

 

I check on the statistics no logs for the destination I am looking to but I can definitely see it on monitor and also on packet capture. 

 

thank you! 

 

0 Kudos
_Val_
Admin
Admin

Sorry, I though I was answering a different thread, disregard the fonts 🙂

0 Kudos
_Val_
Admin
Admin

So, my understanding is, you cannot find logs for certain connections. Do you log all rules? 

0 Kudos
cathychan
Participant

yes we do log all rules.. for some reason only this is not logged 😕

0 Kudos
PhoneBoy
Admin
Admin

Is it a continually active connection (i.e. no TCP FIN/RST) or one that terminates/re-establishes?
If it's continually active, then you will only find a single log entry for the original connection establishment with the bytes updated on that log entry.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events