CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 3 Weeks Ago
foo727 foo727 is offline
Junior Member
 
Join Date: 2007-07-16
Location: Paris
Posts: 14
foo727 has an average reputation (10+)
Default Eventia Reporter R65 : no logs !

Hi all,

I'm using a distributed installation :
Smartcenter is on redhat.
Reporter on SPLAT.
SIC is ok and i can connect to the reporter using the Eventia Reporter client.
I setup a consolidation session in it.

i try to generate a report : all i get is fw_log and cpd, no user traffic !

Maybe I missed something. Do I have to forward the log files to the Reporter ?? It seemed to me that it was automatic...

Thanks for your help
Arno
Reply With Quote
  #2 (permalink)  
Old 3 Weeks Ago
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,463
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Eventia Reporter R65 : no logs !

Did you "install database" on the EVR and smartcenter?
Reply With Quote
  #3 (permalink)  
Old 3 Weeks Ago
foo727 foo727 is offline
Junior Member
 
Join Date: 2007-07-16
Location: Paris
Posts: 14
foo727 has an average reputation (10+)
Default Re: Eventia Reporter R65 : no logs !

yes i did it.
Here is what I did.

I created a checkpoint host in which i checked the Eventia Reporter option (do I have to check log server ??)

I modified the consolidation policy to set all rules to store, so i'm sure to get some consolidation logs.
After that I installed the database.

When i generate a report, the only datas available are :
cpd, fw1-log, icmp, igmp.

Any idea ?
Reply With Quote
  #4 (permalink)  
Old 3 Weeks Ago
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 223
lammbo has an average reputation (10+)
Default Re: Eventia Reporter R65 : no logs !

You don't need to check log server unless you plan on logging to it. Did you check the Eventia Correlation Unit though? That needs to be on as well.

Did you setup the log consolidation job?
If not: Eventia Reporter GUI -> Management -> Consolidation -> Create New
Add the Log server(s), they should be in a pre-populated list. Acccept defaults
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 3 Weeks Ago
foo727 foo727 is offline
Junior Member
 
Join Date: 2007-07-16
Location: Paris
Posts: 14
foo727 has an average reputation (10+)
Default Re: Eventia Reporter R65 : no logs !

I found the problem.
In fact, i'm working on a migration and i didn't know we have the possibility to create several consolidation policies. The customer already created some policies and the default consolidation job relies on a policy which consolidates almost nothing.... I changed this using a custom job and everything works fine now.
Thanks for the help.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:27.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0