Users can enable log forwarding in the Secondary Manager within an MDR pair. This can be done by updating the value of iv.core.mdr.forwarding attribute in the ems.properties file within the Manager server. The possible values to be updated are ['A','F','L','C','N'] or [0], where:
A represents Alerts
F represents Faults
L represents Audit events
C represents Access Control Lists
N represents NTBA Quarantine events
0 is the default value set to the attribute, meaning log forwarding is disabled on the Secondary Manager
To edit the ems.properties file in the Manager, follow these steps:
Windows based Manager server
RDP to the Manager server.
In the
ems.propertiesfile, locate the following:iv.core.mdr.forwarding=0
Go to
<Manager_Install_Dir>\config\ems.propertiesNote
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.To enable log forwarding, assign a value associated with the alerts you plan to forward. An example of enabling fault logs is shown below:
iv.core.mdr.forwarding=F
Note
You can enable single or multiple log types based on your requirement. If you want to enable forwarding multiple log types, enter the values separated by
|. For example, if you want to enable fault and audit logs, update the attribute asiv.core.mdr.forwarding=F|A.Note
If you later plan to disable log forwarding, assign the value
0or any other positive number to the attribute.Save the changes.
Reboot the Manager server.
Linux based Manager server
Log in to the Manager shell.
Execute the
edit ems.propertiescommand.Note
The
editcommand will edit the file using vi-editor. Trellix recommends you to use vi_editor command to perform editing operations on the files.In the
ems.propertiesfile, locate the following:iv.core.mdr.forwarding=0
To enable log forwarding, assign a value associated with the alerts you plan to forward. An example of enabling fault logs is shown below:
iv.core.mdr.forwarding=F
Note
You can enable single or multiple log types based on your requirement. If you want to enable forwarding multiple log types, enter the values separated by
|. For example, if you want to enable fault and audit logs, update the attribute asiv.core.mdr.forwarding=F|A.Note
If you later plan to disable log forwarding, assign the value
0or any other positive number to the attribute.Save the changes.
Execute the
rebootcommand to restart the Manager server.