This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

LEM does not show Client Source IP when reading Kerio Control Logs

Hi guys

i have an issue regarding Kerio Logs when reading those. when i ssh to appliance and read logs i see Kerio is sending logs correctly (at least at it own way) but when i confiure Connector for Kerio Control and want to watch for events there is a big problem. All the Detection IPs are Kerio IP itelf and field related to Machin IP or Client IP is empty. however in SSH i can see which computer or IP addres tried that specific URL. may you help me please ?

thanks in advance

Mohammad    

  • This can most likely be resolved via an update to our Kerio connector. Would you mind raising a Tech Support ticket and passing the ticket number to me? Once we obtain a log sample which shows where the machine/client IP resides in the log line, we should be able to adjust our connector.

  • Dear jhynds

    thanks for your attention

    the deployment is in trial state and I don't know how can i open a support ticket. how ever i am interested to cooperate with your support to solve this issue. our internal sec team are interested also on LEM features. i would be thankful if you guide me to open a ticket.

    best regards

    Mohammad

  • Thanks for confirming Mohammad. One of our Sales Engineers is going to reach out to you (if they haven't been in touch already) to take a look at the logs and work through the parser update with you. Any issues let me know.