Hi Support Tech,
The ProxySG doesn't inherently allow you to offload the same log, and so there are two methods that I am aware of:
1) Have the ProxySG upload to a server, and have the server duplicate and forward the logs to where they need to go.
2) Have the ProxySG make two logs for all traffic (this increases resources used) and then upload one log to reporter, and the other to Splunk.
More info can be found in
this KB.
Thanks!
Original Message:
Sent: 10-13-2020 08:39 PM
From: Support Tech
Subject: Reporter to Splunk
Hi Aboonalm, please can you help me which the method to send logs to additional server like SIEM.
Original Message:
Sent: 06-07-2019 01:05 AM
From: Aboonaim Golandaz
Subject: Reporter to Splunk
Dear Wasfi,
As of is it not possible to send logs to splunk server from Reporter.
But from Proxy, you send logs to additional server like SIEM by creating custom log format.