Hi @kiwi , there are two ways, how to find out, that logs are not being sent to data lake (from the FW perspective) 1) check increasing drop counter for log forwarding (mentioned debug command) 2) check the reason - usualy expired certificate There is no SNMP counter or log for the first one, so you have to do it manualy. You also cannot use API operational command call, because drop info is in debug command and there is no support for debug commands in API. As a workaround, I've configured API call for certificate status (request logging-service certificate info) and than I parse XML output and look for string specific string. It is cumbersome, but better than nothing. Hope, that Data Lake monitoring will be added any time soon. Thank you, Jan
... View more