Jump to content

Archived

This topic is now archived and is closed to further replies.

TomasK

Web control log collecting to ESMC

Recommended Posts

Hi,

I've set up web control with logging level "Always". I'm able to check these logs via the client on the computer...but I would like to collect those logs to ESMC to have global overview.

I tried to create a report according to https://support.eset.com/en/kb6043-log-all-activity-blocked-by-web-control-rules-in-eset-remote-administrator-6x, but the report is empty.

Kind Regards,

ESET Security Management Center (Server), Version 7.2 (7.2.1266.0)
ESET Security Management Center (Web Console), Version 7.2 (7.2.221.0)

Share this post


Link to post
Share on other sites

You must use the "Warning" severity for the desired Web control rules to send the data to ESMC. However, be careful to not use it for rules that allow or block too many urls or it may have adverse effect on perfomance of the ESMC server if many clients start to send a lot of data.

Share this post


Link to post
Share on other sites

Hi Marcos, thanks for fast reply. I will try it.
Is there any way how to collect for example ~2500 clients log data to ESMC without performace issues? Can we optimize it somehow? Right now we have 1 global rule to block specific category groups (6 category groups including it's sub categories).

Share this post


Link to post
Share on other sites

If you want only accessing of one category of urls to be reported to ESMC, it should be fine. The problem could be if you created a rule for every single url with the Warning severity. Since a single client could generate several such records per second, with hundreds or thousands of machines reporting them to ESMC could cause network and server performance issues and congestion.

Share this post


Link to post
Share on other sites

Ok, thanks for reply.

Share this post


Link to post
Share on other sites

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...