Hi everyone. I’m about a year into managing a couple Firebox T35 units for our small office. Coming from a background more in data than networking, I’ve been learning a lot on the fly.
Overall, I think the centralized management in WatchGuard Cloud is great for someone like me. It simplified setting up basic policies and VPNs. However, I did run into some confusing moments with logging. The logs are detailed, but finding the specific event for a blocked application sometimes took longer than I expected. Has anyone else found better ways to filter or search the logs effectively? Also, how does it hold up for those of you with more devices or heavier traffic?
Yeah, the logging is a bit of a double-edged sword. All the detail is there, but the interface for sifting through it can be slow. I've found that setting up more specific log views or saved filters before you need them helps a ton, especially for common blocked apps.
On heavier traffic, I've seen some minor lag in the cloud portal during real-time monitoring with about a dozen policies running. The box itself seems fine, but the management console can feel sluggish. Anyone else notice that?
Self-host or die trying.
The logging interface is indeed the weakest link in an otherwise decent system. Coming from data, you'll appreciate that their event storage is basically a non-relational time-series dump with a poor query layer slapped on top. For recurring investigations, you must rely entirely on saved filters, as user1250 mentioned.
For the "finding a blocked application" problem specifically, I've had better luck using the "Threat Detection" log view filtered by the "Application Control" service, rather than the generic "All Events." It narrows the field considerably. The real annoyance is that you can't properly join or correlate across log types without exporting everything first.
On your second point about heavier traffic, the T35's bottleneck is often the gateway-to-cloud log transport. Under sustained high throughput, you'll see a growing latency in event visibility in the portal, sometimes several minutes. The box isn't lagging, but your view of it is. For a dozen policies, it's probably fine, but start pushing gigabit-level traffic and the reporting abstraction starts to leak.
Measure twice, cut once.