cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1373
Views
5
Helpful
3
Replies

Cisco WSA Access Logs

Dear community,

recently we had to redeploy our WSA due to ongoing authentication issues which I believe is fixed now.

However we were running old WSA for quite a long time now and it contained long history of users access logs.

I have copied files from "accesslogs" folder on old WSA to "accesslogs" folder on new WSA.

While I can see logs in cli - GREP I am not able to search these logs using "Web Tracking" GUI feature. It does not allow me to click on older dates when specifying start date.

Can you please help me on how to correctly transfer access logs from old to new WSA?

Thank you!

1 Accepted Solution

Accepted Solutions

fw_mon
Level 1
Level 1

Hello kamensky@kronovision.sk 

while the grep command accesses log files, the "Web Tracking" feature accesses the reporting DB that built based on requests processed by the WSA appliance. As far as I know you cannot "rebuild" the DB using available access log, you can only delete or disable it. That means even by copying access log from other WSA the "Web Tracking" will not show any records from these logs. This is how it supposed to work. A SMA appliance would keep records from old WSA if a central reporting feature was enabled.

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

i do not believe that works, you can not simply copy old logs to new WSA and expect it to work.

as per I know the old logs need to achieve and retrieve from your any remote syslog server, the new WSA logs will start from the current date to moving forward.

If you have SMA to manage, that will manage all the logs and you can retrieve from SMA.

as per WSA concern that is Limitation as per I know.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

fw_mon
Level 1
Level 1

Hello kamensky@kronovision.sk 

while the grep command accesses log files, the "Web Tracking" feature accesses the reporting DB that built based on requests processed by the WSA appliance. As far as I know you cannot "rebuild" the DB using available access log, you can only delete or disable it. That means even by copying access log from other WSA the "Web Tracking" will not show any records from these logs. This is how it supposed to work. A SMA appliance would keep records from old WSA if a central reporting feature was enabled.

Thank you for replies. We will focus on moving our reporting to SMA then.