Hi,
since you mentioned that you created a tcpdump to check the packets, I assume that you push via syslog!?
I am not aware of any issues/bugs but I have seen cases where journald/syslog was overloaded which resulted into suppressed messages errors on MWG. These cases could be resolved through specific changes in rsyslog.conf. But all this makes only sense if you use syslog and /var/log/messages contains rsyslog related error messages. So, sorry if my syslog assumption is wrong 😊
Nevertheless, I would suggest to open a SR with all details (how do you push, SIEM IP, etc.) and attach feedback file that support can check MWG config (e.g. rsyslog.conf) and log files (mwg-core.errors.log, /Var/log/messages, etc.).
Regards,
Marcel
Regards,
Marcel Kutrieba
Technical Support Engineer
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!