Bit of a strange one that keeps happening in our setup. We've got 2 Azure-based NGFWs running in high availability mode. They are sending logs to our SIEM.
When the primary firewall is active it also sends logs detailing the IPS Blocks that it's made (as well as sending us an email alert). However when the firewalls failover and the secondary one becomes active, the secondary firewall doesn't forward these IPS Block logs to the SIEM. It forwards every other log and we still get an alert email when it's blocked something, but we just don't see any of these blocks in our SIEM. Is there something we may have missed in our config?