<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="fp_web,fp_filter" />
    <META name="version" content="v85" />
    <META name="book" content="Administrator Help for Forcepoint Web Security" />
    <title>Configuring Log Server</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="//support.forcepoint.com/documentation">Documentation</a> | <a class="extLinks" href="//support.forcepoint.com">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="logging_options_explain.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="logdb_test_cxn.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="rpt_admin.aspx">Reporting Administration</a> &gt; Configuring Log Server</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N1H-Heading1"><a name="733830">Configuring Log Server</a></div>
      <div class="IN-TopicInfo"><a name="782947">Administrator Help&nbsp;| Forcepoint Web Security and Forcepoint URL Filtering&nbsp;| v8.5.x</a></div>
      <div class="B-Body"><a name="733840">During installation, you configure certain aspects of Log Server operation, including how Log Server interacts with policy enforcement components. Use the </a><span class="B-Bold">Settings&nbsp;&gt; Reporting&nbsp;&gt; Log Server</span> page to update these settings, or to configure other details about Log Server operation.</div>
      <div class="B-Body"><a name="779114">When you finish your configuration updates, click </a><span class="B-Bold">OK</span> to cache your changes. Changes are not saved until you click <span class="B-Bold">Save and Deploy</span>.</div>
      <div class="B-Body"><a name="779122">If you make changes to the database connection, after saving and deploying the changes, also restart the </a><span class="B-Bold">Websense TRITON&nbsp;- Web Security</span> service on the management server machine to update the database connection for all reporting tools.</div>
      <div class="B-Body"><a name="779115">In multiple Log Server environments, the settings configured on this page apply to the Log Server instance assigned to the Policy Server whose IP address appears on the Web Security toolbar.</a></div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="733849">Verify basic Log Server details</a></div>
      <div class="B-Body"><a name="778563">Under </a><span class="B-Bold">Location</span>, verify the Log Server IP address. If necessary, use the <span class="B-Bold">Port</span> field to update the port over which Log Server communicates with Filtering Service (55805, by default).</div>
      <div class="B-Body"><a name="760944">This port must match the logging port displayed on the </a><span class="B-Bold">Settings&nbsp;&gt; General&nbsp;&gt; Logging</span> page.</div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="778578">Configure the Log Database connection</a></div>
      <div class="B-Body"><a name="760919">Under </a><span class="B-Bold">Log Database Connection</span>, configure the ODBC connection that Log Server uses to connect to the Log Database.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="760978">Specify the ODBC </a><span class="B-Bold">Data source name (DSN)</span> and enter a unique <span class="B-Bold">Description</span> for the database connection.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="773250">Provide the </a><span class="B-Bold">SQL Server location</span> (IP address or hostname and instance name, if applicable) for the Microsoft SQL Server installation that hosts the Log Database, as well as the <span class="B-Bold">Connection port</span> for sending data to the Log Database (1433, by default).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="801411">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="801414">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="801416">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="801426">If a hostname is entered, a DNS lookup will convert it to the IP address of the SQL Server machine and the IP address will be saved in the Policy Server configuration file.</a></div>
          </td>
        </tr>
      </table>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="773251">If your environment uses SQL Server clustering, enter the virtual IP address for the cluster.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="761829">Enter the name of the </a><span class="B-Bold">Default database</span> (wslogdb70, by default).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">5.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="761844">Indicate whether or not to </a><span class="B-Bold">Use SSL to connect to the Log Database</span>. When SSL encryption is enabled:</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="780902">BCP cannot be used to add records to the Log Database.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="780912">Log Database connections are slower, affecting reporting performance.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="771820">&nbsp;</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="771833">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="771835">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="771842">When Microsoft SQL Server components are configured so that "Trust Server Certificate" is set to </a><span class="B-Bold">No</span> (the default), self-signed SSL certificates are not accepted for encryption of database connections.</div>
            <div class="NT-NoteText"><a name="780942">In this case, SSL certificates signed by a Certificate Authority must be properly deployed to the SQL Server, management server, and Log Server machines before you enable the "Use SSL" option in the Forcepoint Security Manager.</a></div>
            <div class="NT-NoteText"><a name="771851">See your SQL Server documentation for information about database encryption.</a></div>
          </td>
        </tr>
      </table>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">6.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="765794">Specify a Log Server connection method:</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="761932">By default, </a><span class="B-Bold">SQL Server authentication</span> is selected. To use SQL Server authentication, provide the SQL Server <span class="B-Bold">Account</span> and <span class="B-Bold">Password</span> to use.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="761972">Alternatively, you can use a </a><span class="B-Bold">Windows trusted connection (network logon account)</span>. The Websense Log Server service must be configured to run as this account.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">7.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="761997">Click </a><span class="B-Bold">Test Connection</span> to verify that it is possible to connect to the Log Database using the credentials provided.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="779153">For information about the tests performed when you click the button, see </a><span class="LEM-LinkEmphasis"><a href="logdb_test_cxn.aspx" title="Testing the Log Database connection">Testing the Log Database connection</a></span>.</div>
      <div class="B-Body"><a name="779129">If you make changes to the database connection, after saving and deploying the changes, also restart the </a><span class="B-Bold">Websense TRITON&nbsp;- Web Security</span> service on the management server machine to update the database connection for all reporting tools.</div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="778604">Specify how log records are processed into the database</a></div>
      <div class="B-Body"><a name="762099">Click </a><span class="B-Bold">Log Record Creation</span> to specify how Log Server adds records to the Log Database.</div>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="B-Bold"><a name="762100">ODBC (Open Database Connectivity)</a></span> inserts records into the database individually, using a database driver to manage data between Log Server and Log Database.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="762108">If you select this option, also set the </a><span class="B-Bold">Maximum number of connections</span> to specify how many internal connections can be made between Log Server and the database engine.</div>
      <div class="I-IndentedText"><a name="762141">Select a value between 4 and 50, as appropriate for your SQL Server license.</a></div>
      <div class="F-Frame"><a name="762323">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="762352">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="762354">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="762355">Increasing the number of connections can increase processing speed for log records, but could impact other processes in the network that use the same SQL Server. In most cases, you should set the number of connections to fewer than 20. Contact your Database Administrator for assistance.</a></div>
          </td>
        </tr>
      </table>
      <div class="B1-Bullet1_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B1-Bullet1_inner" style="width: 18pt; white-space: nowrap">
                <img src="b1.png" alt="*" border="0" width="8" height="8" />
              </div>
            </td>
            <td width="100%">
              <div class="B1-Bullet1_inner"><span class="B-Bold"><a name="762036">BCP (Bulk Copy Program)</a></span> (<span class="EM-Emphasis">recommended</span>) inserts records into the Log Database in batches. This option offers better efficiency than ODBC insertion, and is selected by default if the <span class="B-Bold">bcp.exe</span> file is found on the machine.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="775653">The BCP option is available only if you install the SQL Server Native Client and Command Line Utilities on the Log Server machine. To allow the BCP option to be available by default, when Log Server is installed on a machine, the SQL tools are installed also.</a></div>
      <div class="I-IndentedText"><a name="775637">BCP cannot be used when SQL Server SSL encryption is used.</a></div>
      <div class="I-IndentedText"><a name="762023">If you select the BCP option, also specify:</a></div>
      <table class="BodyTable" style="margin-left: 18pt; text-align: left" summary="">
        <caption></caption>
        <tr>
          <td style="background-color: #666465; border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: 2px; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: 2px; border-top-color: #808080; border-top-style: solid; border-top-width: 2px; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CH-CellHeading"><a name="762419">Option&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</a></div>
          </td>
          <td style="background-color: #666465; border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: 2px; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: 2px; border-top-color: #808080; border-top-style: solid; border-top-width: 2px; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CH-CellHeading"><a name="762421">Description&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762423">BCP file location</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762425">Directory path for storing BCP files. Log Server must have read and write access to the location. (The default folder is C:\Program Files\Websense\Web Security\bin\Cache\BCP.)</a></div>
            <div class="CB-CellBody"><a name="762426">After entering the path, click </a><span class="B-Bold">Test Location</span> to verify that the location is accessible.</div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762428">File creation rate</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762430">Maximum number of minutes Log Server spends placing records into a batch file before closing that batch file and creating a new one. </a></div>
            <div class="CB-CellBody"><a name="762431">This setting works in combination with the batch size setting: Log Server creates a new batch file as soon as either limit is reached.</a></div>
          </td>
        </tr>
        <tr>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762433">Maximum batch size</a></div>
          </td>
          <td style="border-bottom-color: #808080; border-bottom-style: solid; border-bottom-width: thin; border-left-color: #808080; border-left-style: solid; border-left-width: thin; border-right-color: #808080; border-right-style: solid; border-right-width: thin; border-top-color: #808080; border-top-style: solid; border-top-width: thin; padding-bottom: 3.5pt; padding-left: 6pt; padding-right: 6pt; padding-top: 4.5pt; vertical-align: top">
            <div class="CB-CellBody"><a name="762435">Maximum number of log records before a new batch file is created.</a></div>
            <div class="CB-CellBody"><a name="762436">This setting works in combination with the creation rate setting: Log Server creates a new batch file as soon as either limit is reached.</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="762475">After selecting a log record insertion method, click </a><span class="B-Bold">Log Cache Files</span> to specify where and how log cache files are created. These provide temporary storage for log records that have not yet been processed into the Log Database or moved to BCP files.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762583">For </a><span class="B-Bold">Cache location</span>, indicate where on the Log Server machine logging cache files are stored (C:\Program Files\Websense\Web Security\bin\Cache\, by default).</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762485">Click </a><span class="B-Bold">Test Location</span> to verify that the path is accessible.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762511">For </a><span class="B-Bold">Cache file creation rate</span>, indicate the maximum number of minutes (1, by default) Log Server should spend sending Internet access information to a log cache file before closing it and creating a new file.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762513">For </a><span class="B-Bold">Maximum cache file size</span>, specify how large a log cache file should be before Log Server closes it and creates a new one. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B-Body"><a name="762498">The file creation rate and maximum file size settings work in combination: Log Server creates a new log cache file as soon as either limit is reached.</a></div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="778662">Adjust database sizing settings</a></div>
      <div class="B-Body"><a name="762608">Configure </a><span class="B-Bold">Database Size Management</span> settings to meet your organization's needs. The higher the level of detail recorded, the larger the Log Database.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="775701">To minimize the size of the Log Database, mark </a><span class="B-Bold">Enable log record consolidation</span>. This combines multiple, similar Internet requests into a single log record, reducing the granularity of reporting data.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="775702">If you have enabled SIEM integration, note that Log Server applies consolidation to the log records that it processes into the Log Database. Consolidation does not occur for records passed to the SIEM product.</a></div>
      <div class="I-IndentedText"><a name="775707">When consolidation is enabled, requests that share all of the following elements are combined into a single log record:</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762815">Domain name (for example: www.forcepoint.com)</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762816">Category</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762817">Keyword</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762818">Action (for example: Category Blocked)</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762819">User/IP address</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="762884">The log record includes the number of requests combined into the consolidated record, as well as the total bandwidth for all of the consolidated requests.</a></div>
      <div class="I-IndentedText"><a name="772329">Reports run faster when the Log Database is smaller. However, consolidation may decrease the accuracy of some detail reports, as separate records for the same domain name may be lost.</a></div>
      <div class="F-Frame"><a name="762910">&nbsp;</a></div>
      <table class="ImpTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="II-ImpIcon">
              <img src="important.gif" alt="*" border="0" width="30" height="34" /><a name="762880">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="IMP-Important">
              <span class="Bold">Important</span><a name="762882">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="762883">To assure consistent reports, create a new database partition whenever you enable or disable consolidation. Also, be sure to generate reports from partitions with the same consolidation setting.</a></div>
          </td>
        </tr>
      </table>
      <div class="I-IndentedText"><a name="762785">With Forcepoint Web Security, when consolidation is enabled, numbers shown in reports that include traffic blocked by scanning are </a><span class="B-Bold">lower</span> than the numbers shown on reports about Content Gateway analysis. This is a side-effect of the way that analytic activity is recorded.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762929">If you enable consolidation, also specify the </a><span class="B-Bold">Consolidation time interval</span>. This represents the greatest allowable time difference between the earliest and latest records combined to make one consolidation record. </div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="762931">Decrease the interval to increase granularity for reporting. Increase the interval to maximize consolidation. Be aware that a larger interval can also increase usage of system resources, such as memory, CPU, and disk space.</a></div>
      <div class="I-IndentedText"><a name="762934">If you enable full URL logging on the </a><span class="B-Bold">Settings&nbsp;&gt; Reporting&nbsp;&gt; Log Database</span> page, consolidated log records contain the full path (up to 255 characters) of the first matching site Log Server encounters.</div>
      <div class="I-IndentedText"><a name="762935">For example, suppose a user visited the following sites and all were categorized in the shopping category.</a></div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762936">www.domain.com/shoeshopping</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762937">www.domain.com/purseshopping</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="762938">www.domain.com/jewelryshopping</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="762939">With full URL logging enabled, consolidation creates a single log entry showing 3 requests for the URL www.domain.com/shoeshopping.</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="762798">Under Hits and Visits, use the </a><span class="B-Bold">Enable visits</span> check box to indicate the level of granularity recorded for each user Internet request.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="F-Frame"><a name="763232">&nbsp;</a></div>
      <table class="NoteTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="NI-NoteIcon">
              <img src="note.gif" alt="*" border="0" width="33" height="33" /><a name="763253">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="N-Note">Note<a name="763255">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="763256">It is best to create a new database partition prior to changing the method of logging between visits and hits. See the </a><span class="B-Bold">Settings&nbsp;&gt; Reporting&nbsp;&gt; Log Database</span> page to create a new database partition. </div>
          </td>
        </tr>
      </table>
      <div class="I-IndentedText"><a name="762982">When this option is </a><span class="B-Bold">not</span> selected, a separate log record is created for each HTTP request generated to display different page elements, including graphics, advertisements, embedded videos, and so on. Also known as logging hits, this creates a much larger Log Database that grows rapidly.</div>
      <div class="I-IndentedText"><a name="763072">When this option </a><span class="B-Bold">is</span> selected, Log Server combines the individual elements that create the web page (such as graphics and advertisements) into a single log record that includes bandwidth information for all elements of the visit.</div>
      <div class="I-IndentedText"><a name="763120">With Forcepoint Web Security, when visits are enabled, numbers shown in reports that include traffic blocked by real-time analysis are </a><span class="B-Bold">lower</span> than the numbers shown on Content Gateway analysis-specific reports. This is a side-effect of the way that analytic activity is recorded.</div>
      <div class="N2HN-HeadNoTopic2">
        <span class="Heading_Number"></span><a name="778928">Configure User Service communication</a></div>
      <div class="B-Body"><a name="763284">Click the </a><span class="B-Bold">User Service Connection</span> button, then use the <span class="B-Bold">User and group update interval</span> field to indicate how often Log Server connects to User Service to retrieve full user name and group assignment information (ever 12 hours, by default).</div>
      <div class="B-Body"><a name="763333">Activity for a user whose user name or group information has changed continues to be reported with the original user name or group assignment until the next update occurs. Organizations that update their directory service frequently or have a large number of users should consider updating the user/group information more frequently.</a></div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="logging_options_explain.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="logdb_test_cxn.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="rpt_admin.aspx">Reporting Administration</a> &gt; Configuring Log Server</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2023 Forcepoint. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:webhelp_v85x:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>