cancel
Showing results for 
Search instead for 
Did you mean: 
ZanG
Level 8
Report Inappropriate Content
Message 1 of 1

A problem with MWG logs in SIEM

Hi,

I am using MWG 8.1.5 and RSA Netwitness 10.6.6 SIEM. I noticed that not all MWG events come into siem. For example I visited a web site multiple times. The site was always loged in the MWG log, but that log did not always arrive into siem. I also did a tcpdump on the siem server to see if the packet containing that info came into siem or not. Sometimes it did, sometimes it didn't (like I mentioned before MWG log always contained the information that the site was visited). I would like to know if there could be something wrong with MWG, or this problem is entirelly on the siem's side?

Thank you very much.

Best regards

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community