Go to the table of contents Go to the previous page You are at the end of the document View or print as PDF
Getting started with SIEM Integration : Troubleshooting SIEM logging using Forcepoint storage
Troubleshooting SIEM logging using Forcepoint storage
Forcepoint Web Security Cloud | Getting started with SIEM Integration
Your download script attempts to connect to the cloud service to download SIEM logs at an interval that you configure. If your script is unable to make the connection, or if it is unable to retrieve the log files after connecting, the following problems may occur:
*
*
To address this issue:
*
*
*
*
If you do not download logs for a period of 7 days, an email is sent to all administrative contacts with Log Export permission enabled, and all policy administrators where full traffic logging is enabled for the policy, notifying them that data has not yet been downloaded. At 13 days, a different email warns that data may be lost; it is deleted at 14 days. Further notifications are sent after 21 days to warn that the process will be disabled if not used. After 30 days you will be notified that SIEM logging has been deactivated and reporting logs are no longer being generated for your account.
 
 
©2022 Forcepoint. Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint. All other trademarks used in this document are the property of their respective owners.
Document last updated: July 19, 2022
 

Go to the table of contents Go to the previous page You are at the end of the document View or print as PDF
Getting started with SIEM Integration : Troubleshooting SIEM logging using Forcepoint storage
Copyright 2022 Forcepoint. All rights reserved.