Log files getting emailed randomly.
ratherman
Newbie ✭
I have latest 6 different TZ firewalls (different models) (GEN6) - latest firmware, that appear to be sending logs quite often (and randomly). I originally had them set to send when full. I am getting emails with only 10-20 entries. I changed them to once per week and seeing the same issue. I do know that they will send when the buffer is full - but the logs are so small I find that hard to believe. Lokking for suggestions and/or things to look at.
Thank you,
Category: Entry Level Firewalls
Tagged:
0
Answers
Do you have access to logs on mail server where it submits mails to?
From memory, the log is split into multiple emails. Is it consistently the nth one every time or is it random?
Well, the email server is the same one that gets the logs from (7) GEN7 firewalls, and those work fine. I understand about the logs being split into multiple emails - but they are Part 1 (of 1) and, for example, only have 5 entries in the logs. The firewalls should not be sending those.
I think I figured it out - just because I have entries not included in EMAILSs, they are still included in the GUI - and I found some entries with a lot of hits - which is what is filling up the buffer. The emails are short and the entries that are filling the buffer are not included.
Ah makes sense. Good catch.