<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; incorrect size &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/tag/incorrect-size/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Forefront TMG logs size fields the wrong way around</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 04:49:04 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[bytes received]]></category>
		<category><![CDATA[bytes sent]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[incorrect size]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2011</guid>
		<description><![CDATA[If you&#8217;re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs &#8211; both SQL and W3c . We noticed in a few web reports, that people were generally uploading a [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs &#8211; both SQL and W3c . We noticed in a few web reports, that people were generally uploading a lot more than they were downloading. So we checked the logs and verified the buggy behavior:<span id="more-2011"></span></p>
<div id="attachment_2012" class="wp-caption alignleft" style="width: 610px"><img class="size-full wp-image-2012" title="Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/TMG-Bytes-Sent-Greater-than-Bytes-Receieved-e1280372795595.png" alt="Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received" width="600" height="261" /><p class="wp-caption-text">Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received</p></div>
<p><strong>This issue has been confirmed by the Microsoft Forefront TMG team, and unfortunately there is no ETA for a fix.</strong></p>
<p>We obviously don&#8217;t want our reports showing incorrect usage figures, so we&#8217;ve fixed our TMG loader so that it imports the &#8216;bytesrecvd&#8217; field into the Bytes Sent aggregate, and the &#8216;bytessent&#8217; field into the Byte Received aggregate.</p>
<p>But what if Microsoft release a fix? What we&#8217;ve done is implemented a loader property to allow you to turn off this behavior. This will allow you to import your old logs with the fields reversed, and your new logs with the fields the right way around.</p>
<p>To access the loader property:</p>
<ul>
<li> On the import wizard, select the Microsoft FTMG format and click the <strong>Properties </strong>button on the toolbar</li>
<li> Select Microsoft FTMG from the drop down list</li>
<li> Notice the option to &#8216;Reverse Bytes Sent and Received to compensate for bug in TMG&#8217;s logging&#8217;. Leave this checked until Microsoft issue a fix.</li>
</ul>
<div id="attachment_2024" class="wp-caption alignleft" style="width: 610px"><img class="size-full wp-image-2024" title="Microsoft TMG Option to Reverse Bytes Sent and Received" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/TMGReverseSentReceivedOption-e1280378741711.png" alt="Microsoft TMG Option to Reverse Bytes Sent and Received" width="600" height="386" /><p class="wp-caption-text">Microsoft Forefront TMG Loader Option to Reverse Bytes Sent and Received</p></div>
<p>This fix is available in <a title="Vantage Update 2.2.0.48 – New Loaders, Features and Fixes " href="http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/" target="_blank">Vantage build 2.2.0.48</a> (and above) which has been released as an auto update. So simply select<strong> Tools | Check for updates</strong> to ensure you have this fix.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

