Menu item disappeared under System Log File "WAF Event Log File"

0

Just this morning I logged into our KEMP WAF and under "System Configuration" I selected "Logging Options" . In the menu I had 7 options.  This afternoon I log back in and I only see 6 options.  The "WAF Event Log File" is no longer present.  I talked to the admin and he says he has not changed anything.  

The information in the "WAF Event Log File" provides me the information I need while performing investigations.  The information in the "Extended Log Files" -> "WAF Audit Log" is not as useful to perform my needed tasks.  Any Help would be greatly appreciated.  

Regards,

Shane 

4 comments

Avatar
0
Michael Immendorfer

Hi Shane,

I have confirmed that this logging option disappears from version 7.2.42 onwards only if the WAF Event Log is empty.  I tested this myself to ensure the behavior is still accurate.  Without any logs, there is no WAF Event Log file.  When I trigger a rule the file then appears.

If this is not the behavior you are seeing I would advise creating a support ticket containing your backup/logs so our team can take a deeper look at this.

Thanks!

Avatar
0
sruby

Thank you Michael,  Excellent Answer,   

One follow up question.  When a KEMP WAF does a fail over from Standby to Active (etc...).  Should the logs follow or does it start over as empty?  Or if it is empty; would that be considered an issue with the configuration of the pair?   Thank you again Michael

Regards,

Shane 

Avatar
0
Michael Immendorfer

Shane,

Tested myself to be sure.  If your LM fails over, the WAF Event Logs do not populate on the new machine so yes, they start over as empty.  These logs do however persist through a reboot on the individual units.

So a failover or the clearing of logs could cause the WAF Event Log File to disappear.  Hopefully this helps.  For any further assistance feel free to reach out to our support team!

Thanks,

Mike

Avatar
0
sruby

Thank you Mike,  This is excellent information.  I passed this info along to our System Admin.

 

Again, Thank you for your quick response Mike