The deployment consists of more than a single ProxySG appliance sending access logs to the Reporter server, but these Log Sources all feed into the same database. Can I identify what data came from what ProxySG appliance?
Steps
Where in the access log is this information found?
This information is reported on the header of each access log, per the following sample
#Software: SGOS 5.4.0.3
#Version: 1.0
#Start-Date: 2008-12-31 23:51:02
#Date: 2008-12-29 16:59:46
#Fields: date time time-taken c-ip cs-username cs-auth-group x-exception-id sc-filter-result cs-categories cs(Referer) sc-status s-action cs-method rs(Content-Type) cs-uri-scheme cs-host cs-uri-port cs-uri-path cs-uri-query cs-uri-extension cs(User-Agent) s-ip sc-bytes cs-bytes x-virus-id
#Remark: 1507060048 "home 200 yo" "192.168.13.4" "main"
2008-12-31 23:52:04 120 192.168.13.100 - - - OBSERVED "Email" http://us.mg2.mail.yahoo.com/dc/launch?.rand=3n7ub0sah9n1r 200 TCP_NC_MISS GET text/xml;%20charset=UTF-8 http us.mg
NOTE: The above IP address is the primary address on the box, which is the lowest numbered interface. Therefor, if interface 0:0 has an IP address configured, this is the address it would choose.