How to configure Edge SWG to forward access logs to Cloud SWG Hosted Reporting service directly via SCP
Sending ProxySG appliance logs to Cloud Secure Web Gateway requires the use of secure copy (SCP). You must create and download a private key and use it to copy the logs to the service.
During WSS add-on - Hosted Reporting initial setup wizard download the client private key. If needed, the same key can be re-created logging into the Cloud Secure Web Gateway portal (@https://cloudswg.symantec.com/) and going to "Account Configuration -> Hosted Reporting" and clicking on the "Recreate and Download SCP Key" button.
In the Edge SWG set the specific access log (example "main") client to use SCP and set the Cloud SWG Hosted Reporting provided server, example:
SSH to the Edge SWG and set the specific access log (example "main") SCP client to authenticate thanks to RSA key:
All Edge SWG ciphers, HMACs, and known hosts for outbound SSH connections stored on the appliance are available for selection and review in the Management Console ("Configuration > Authentication > SSH Outbound Connections"), example:
EdgeSWG#(config)ssh-client
EdgeSWG#(config ssh-client)client-keys
EdgeSWG#(config ssh-client client-keys)view
% No keys defined
EdgeSWG#(config ssh-client client-keys)# inline rsa my_eof_marker
-----BEGIN RSA PRIVATE KEY-----
MIIJJwIBAAKCAgEAqekg236CruqwnA/PFeQ6732gEsyPNDRx2MqytA7XT/+4yMQz
...
ISsH+c2stDoGNSQjqydabj9ypHdadvryswplwNdUT2/MJt0/h1R+7Eik5g==
-----END RSA PRIVATE KEY-----
my_eof_marker
ok
EdgeSWG#(config ssh-client client-keys)view
RSA public key:
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCp6SDbfoK ...
Test specific access log upload from Edge SWG "Administration -> Logging -> Access Logging" "Logs -> (example) main" either clicking on "Test Upload" or "Upload Now" buttons. Check SGOS event log records, example of a successful test and upload:
Check in the Cloud SWG tenant Reports that the on premises Edge SWG forwarded access log records are present. It can take up to 5-10 minutes for the data to be processed and displayed. Example: