Blue Coat Proxy logs are compressed in GZIP format and must be unpacked before they are processed by the collector.
A script to unpack the Blue Coat logs is provided in the
utils folder of the collector installation package and is named
The default Windows directory for the managegzs.cmd file is C:\Program Files\collectors\bluecoat_proxy\utils.
The default Linux directory for the managegzs.cmd file is: ../collectors/bluecoat_proxy/utils
You can edit the managegzs.cmd script by setting the following directory location variables:
* Set the BLUECOAT_GZ_FILE_DIR directory to the location of the compressed BlueCoat logs.
* Set the GZIP_OUTPUT directory to the location that stores the uncompressed logs.
Note: You should schedule the
managegzs.cmd script to run frequently enough so that the uncompressed logs are always available for the collector.
For more information, see the
Symantec Event Collectors Integration Guide.