Right, that's in accordance with what I suspected.
My question and goal lies in this sentence exactly:
@reaper wrote:
in the unfiltered ACC dashboard, you will actually get to see 'hardware' counters directly off the dataplane, once you drill down into a filtered view, you will access the log database and will only be presented with data that has been logged
This is the issue I'm trying to address, it's not that I want to clear out the counters, it's that I want to start logging because of the counters. I understand that you can just flip logging on to a bunch of policies, but ping is not exactly something handled exclusively by policies. Often the policy handles other apps as well. I don't want to log the other apps because that'll lead to quite an increase in average logging.
That's why I want to know if there's any plans for alternate methods for logging. Such as logging policies that don't affect blocking/allowing/alerting/dropping.
I'm also still all ears for anyone who can come up with something simpler than trying to come up with a "wrapping policy" that, for over 300 policies, will not be just a side project. Just to log all instances of ping for a period of time.
Because once the instances are logged, THEN I can see the reports that I need.
... View more