TomasK 0 Posted July 15, 2020 Posted July 15, 2020 Hi, I've set up web control with logging level "Always". I'm able to check these logs via the client on the computer...but I would like to collect those logs to ESMC to have global overview. I tried to create a report according to https://support.eset.com/en/kb6043-log-all-activity-blocked-by-web-control-rules-in-eset-remote-administrator-6x, but the report is empty. Kind Regards, ESET Security Management Center (Server), Version 7.2 (7.2.1266.0)ESET Security Management Center (Web Console), Version 7.2 (7.2.221.0)
Administrators Marcos 5,462 Posted July 15, 2020 Administrators Posted July 15, 2020 You must use the "Warning" severity for the desired Web control rules to send the data to ESMC. However, be careful to not use it for rules that allow or block too many urls or it may have adverse effect on perfomance of the ESMC server if many clients start to send a lot of data. TomasK 1
TomasK 0 Posted July 15, 2020 Author Posted July 15, 2020 Hi Marcos, thanks for fast reply. I will try it. Is there any way how to collect for example ~2500 clients log data to ESMC without performace issues? Can we optimize it somehow? Right now we have 1 global rule to block specific category groups (6 category groups including it's sub categories).
Administrators Marcos 5,462 Posted July 15, 2020 Administrators Posted July 15, 2020 If you want only accessing of one category of urls to be reported to ESMC, it should be fine. The problem could be if you created a rule for every single url with the Warning severity. Since a single client could generate several such records per second, with hundreds or thousands of machines reporting them to ESMC could cause network and server performance issues and congestion. TomasK 1
Recommended Posts