Jump to content

Web control log collecting to ESMC


TomasK

Recommended Posts

Hi,

I've set up web control with logging level "Always". I'm able to check these logs via the client on the computer...but I would like to collect those logs to ESMC to have global overview.

I tried to create a report according to https://support.eset.com/en/kb6043-log-all-activity-blocked-by-web-control-rules-in-eset-remote-administrator-6x, but the report is empty.

Kind Regards,

ESET Security Management Center (Server), Version 7.2 (7.2.1266.0)
ESET Security Management Center (Web Console), Version 7.2 (7.2.221.0)

Link to post
Share on other sites
  • Administrators

You must use the "Warning" severity for the desired Web control rules to send the data to ESMC. However, be careful to not use it for rules that allow or block too many urls or it may have adverse effect on perfomance of the ESMC server if many clients start to send a lot of data.

Link to post
Share on other sites

Hi Marcos, thanks for fast reply. I will try it.
Is there any way how to collect for example ~2500 clients log data to ESMC without performace issues? Can we optimize it somehow? Right now we have 1 global rule to block specific category groups (6 category groups including it's sub categories).

Link to post
Share on other sites
  • Administrators

If you want only accessing of one category of urls to be reported to ESMC, it should be fine. The problem could be if you created a rule for every single url with the Warning severity. Since a single client could generate several such records per second, with hundreds or thousands of machines reporting them to ESMC could cause network and server performance issues and congestion.

Link to post
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...