So...from the Connection Managers I enabled syslog output to a UNC share. We used our Arcsight server to collect those logs and sure enough, source IP info from Security Server connections are there along with internal connections. I appreciate the info guys.
↧