Home / Resources / Log Forwarding
Send what the console records to the system where you keep everything else.
Both logs, and they answer different questions. Access events are who connected to what, and what was blocked. Audit events are who changed a setting, what they changed it from, and when. Forwarding one without the other leaves a gap that is usually noticed during an incident.
Nothing in the product stops working. Forwarding is a copy, not the record: the console remains the system of record, so an unreachable SIEM costs you the stream, not the history. Check the destination if events stop arriving, then look at the logs in the console to confirm they are still being written.
Most failures are the same three things: a port that is closed between the two, a collector expecting a different format, and a destination that resolves internally but not from where the console runs.