This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why the live log ( web filtering) can't show the expected result?

Hi all,

 I want to check my live log at "live log : web filtering".

Following is my steps:

1) Open the live log window on Web Protection | Web Filtering

2) At "filter" , I input my IP. For example : 10.77.192.90

3) Click Reload

4) Go to any website. For Example : https://web.whatsapp.com

5) Search the string in the log 

 

Problem:

1) The log result hasn't the IP. From the results, I can't search my IP in there. I am afraid that log is not related to me.

2) The log result hasn't the "whatsapp" string.

 

Does I have any steps are not correct to affect the result? 

Thanks a lot!



This thread was automatically locked due to age.
  • The live log can be confusing.   The short answer is that you need to be patient for everything to display.

    No matter how fast you type your filter string, the live log will always fill with one page of unfiltered content.   These entries can be ignored.

    I always use the [Enter] key after typing my search string.   I do not know if it is necessary, but it makes me feel more confident that UTM received my filter request.

    After the filter is entered, begin your tests.   Do not use the LiveLog PC for your tests, as the LiveLog updates will become LiveLog entries, and confuse things.

    The entries from your test system will appear after a delay of a few seconds, not instantly.   You may need to scroll down to see all of the new data.

    The live log is not searchable, so I use Ctrl/A to select everything in the live log window, then Ctrl/C to put it in my buffer so I can paste it into a test editor.   WordPad (Win10) and Write (Win7) are recommended, but it formats the results better than Notepad.   

    Then I search for the first occurrence of my filter string and delete everything that precedes that entry, to remove the clutter.

    At this point, I can browse or search to evaluate my test results.

  • DouglasFoster said:

    The live log can be confusing.   The short answer is that you need to be patient for everything to display.

    No matter how fast you type your filter string, the live log will always fill with one page of unfiltered content.   These entries can be ignored.

    I always use the [Enter] key after typing my search string.   I do not know if it is necessary, but it makes me feel more confident that UTM received my filter request.

    After the filter is entered, begin your tests.   Do not use the LiveLog PC for your tests, as the LiveLog updates will become LiveLog entries, and confuse things.

    The entries from your test system will appear after a delay of a few seconds, not instantly.   You may need to scroll down to see all of the new data.

    The live log is not searchable, so I use Ctrl/A to select everything in the live log window, then Ctrl/C to put it in my buffer so I can paste it into a test editor.   WordPad (Win10) and Write (Win7) are recommended, but it formats the results better than Notepad.   

    Then I search for the first occurrence of my filter string and delete everything that precedes that entry, to remove the clutter.

    At this point, I can browse or search to evaluate my test results.

     

     

    Hi DouglasFoster,

    I don't know why. After I reboot the firewall , it works again!

    If I hope to set two criterion at Filter. is it possible?

    For Example: IP "10.77.192.90" with "Whatsapp" String

  • I have nit tried that.  It may be a regular expression match.   So turn it into  regex syntax and try it.

    Have you checked to see if Application Control can detect WhatsApp?

  • DouglasFoster said:

    I have nit tried that.  It may be a regular expression match.   So turn it into  regex syntax and try it.

    Have you checked to see if Application Control can detect WhatsApp?

     

    Hi DouglasFoster,
    After I click the Open Flow Monitor Button, the prompt window will show the "Whatsapp" at Application field.  If check the Detail on WhatsApp, it has always been "No data available in table".