Hi,
I am trying to send McAfeeWeb Gateway access.log to CSR over Syslog.
CSR version: 2.7
Attachec Error Messages
I don't find any document about the correct log header to use.
Please help!
Thanks
Solved! Go to Solution.
Hi @uchiha
the log header is configured in default log handler for Access.log if you follow for example this article:
https://kc.mcafee.com/corporate/index?page=content&id=KB77988
UI > Policy > Settings > Access Log Configuration
Header:
time_stamp "auth_user" src_ip status_code "req_line" "categories" "rep_level" "media_type" bytes_to_client bytes_from_client "user_agent" "virus_name" "block_res" "application_name"
Hi @uchiha
the log header is configured in default log handler for Access.log if you follow for example this article:
https://kc.mcafee.com/corporate/index?page=content&id=KB77988
UI > Policy > Settings > Access Log Configuration
Header:
time_stamp "auth_user" src_ip status_code "req_line" "categories" "rep_level" "media_type" bytes_to_client bytes_from_client "user_agent" "virus_name" "block_res" "application_name"
Hello @uchiha
2021-01-09 19:34:15,566 WARN [com.mcafee.mesa.logparsing.parsers.builtins.ParseWebWasher]
Missing URL field. Log format line invalid. (line=
#time_stamp url_host auth_user src_ip status_code req_line categories rep_level
media_type bytes_to_client user_agent virus_name block_res url_raw
)
you have to check not only the header line but also the actual log structure (UI > Policy > Log Handler > Default > access.log ) which have to correspond with the header line.
Post here screenshots of your access log configuration and access log structure
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA