Forum Discussion

AhmedSaied_2402's avatar
AhmedSaied_2402
Icon for Altostratus rankAltostratus
Feb 16, 2018

ASM event logs do not show logs of last two days

We have checked all event logs of all profiles last logs appear 2 days ago

 

We have noticed that logging on a lot of virtual servers was set as log all request, we have changed it to log only illegal requests.

 

We have to wait a time and logging will be adjusted or we have to modify something or execute commands

 

2 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    The logging change should be immediate. Any error messages in /var/log/asm or bd.log?

     

    Are you logging remotely? If in a HA pair, what about if you fail over to the passive device, does that log successfully?

     

    N

     

  • check disk space. logging locally sends it to the mysql database for asm. so if its full, it'll get truncated at some point but worth to check.

     

    check via packet capture if when an illegal request is triggered, does the event log sent to the SIEM. depends on which interface the SIEM is reachable from - either mgmt interface or a self ip.