10-19-2022 01:18 AM - edited 10-19-2022 01:21 AM
I hope you are doing well : )
I recently received an EDL-related question from a customer, but I couldn't find an answer, so I want to ask for advice.
The customer's configuration is the configuration set by the blacklist IP on the EDL
However, the blacklist IP should be checked in the traffic log, but it can be checked in the treatment log.
Is this expected action?
Then can you tell me why the log is recorded in the Treat log tab?
10-19-2022 07:41 AM
I would suggest they use the 'Unified' log. This shows all the other logs all together. I find its more helpful than jumping from different logs, etc.
Another thing they could try is to put a 'Tag' on the policy that utilizes the EDL. This way they can just filter by the 'Tag'
10-19-2022 05:08 PM
Thank you for sharing the information.
If so, is it normal work for the IPs set in the EDL to be logged in the Treat log?
10-21-2022 07:14 AM
10-23-2022 05:06 PM - edited 10-23-2022 05:07 PM
Thank you for replying .
I have tested EDL in a DENY rule, it is displayed in the Traffic logs.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!