following my earlier 'guest' post I have been playing with the settings using both Syslog and Webtrends reporting from a Netscreen 25.
You said I should only select one of these, so I have now selected Syslog on port 514. I have deleted the second syslog server running on port 1514. Is that normal? When I selected the Listening Ports option I had a number of 1514 and 514 ports listed.
Also, the Live Report kbps graph doesn't seem to update the data line. The time grid moves with the clock, but unless I shutdown and restart the analyzer server the graph doesn't get updated. Is there a way to refresh the graph without shutting down and restarting.
The Live Report also has a highlight, whcih when selected says that the 'Intranet settings have not been configured'. I have tried to add an IP Network (192.168.17.0 255.255.255.0) but when I select SAVE SETTINGS I get a response: Given Network Address is not an IPV4 Address. Any suggestions on how to fix this and is this important?
Is there a way to get the analyzer to reprocess the existing data, ie a refresh. I ask becuase if you go through and allocate 'unassigned' protocols, they remain in the unassigned. A re-read of the data would move these itens into the new protocol groups.
Is there a way to see the data records that have come from the firewall? Are they stored in a file that can be opened for examination or checking? I had to add some 'unassigned' protocols to groups, eg SMTP (TCP). I'm curious as to whether it was sent from syslog or the webtrends reporting. It seems strange that if you support Netscreen native then why would I have to add these unassigned protocols.