After upgrading Symantec SpanVA to version 1.15.3.170.0 or higher, logs uploaded from Symantec Edge SWG (ProxySG) are no longer processed or visible in the CloudSOC Audit dashboard. This occurs due to new security hardening that requires an encrypted connection for all log transfers.
SpanVA version 1.15.3.170.0 introduces FTPS Enforcement. The internal vsftpd configuration is hardened to reject plain, unencrypted FTP connections and requires SSL/TLS encryption (FTPS) for both server and client communications. External FTP servers/clients that communicate with SpanVA must now support FTPS.
To restore log ingestion, the upload client must be reconfigured to use secure protocols.
To enable FTPS on Edge SWG, refer to the online documentation for enabling SSL on FTP:
Configure an Upload Client on Edge SWG
If the FTPS client is configured to verify peer certificates, you must import the SpanVA certificate into the Edge SWG.
For further assistance with Edge SWG configuration, please refer to Article 165325.