<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs from Infinity Portal to Splunk in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193423#M241</link>
    <description>&lt;P&gt;Point 3, correct.&lt;/P&gt;
&lt;P&gt;Point 1, yes, that is the case.&lt;/P&gt;
&lt;P&gt;Point 2, not 100% sure, but you may want to confirm with TAC.&lt;/P&gt;
&lt;P&gt;Example I gave you was that my colleague and I had TAC set up cp log export so logs from S1C (smart 1 cloud) would go to SIEM.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sat, 23 Sep 2023 18:52:31 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-09-23T18:52:31Z</dc:date>
    <item>
      <title>Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193380#M235</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I need to feed SPLUNK with logs from Infinity Portal.&lt;/P&gt;&lt;P&gt;I read that with Infinity Portal all logs and security events are stored in the Infinity Portal’s cloud-native as datalake in cloud.&lt;/P&gt;&lt;P&gt;It can forwarding events, as said in the doc, as "...an easy and secure procedure to export Infinity Portal data over the Syslog protocol. You can forward logs, events, and saved application data from your Check Point Infinity Portal account to a&lt;BR /&gt;SIEM (Security Information and Event Management) provider, such as Splunk, QRadar, or ArcSight".&lt;/P&gt;&lt;P&gt;In my case I want to send these event to a Splunk ES (SaaS cloud)&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;How Can i choice the format of the log since there are different log format vendor SIEM as CEF, LEEF, maybe json for SPLUNK ?&lt;/LI&gt;&lt;LI&gt;If there is a solution for the point 1 do i need to set up a Splunk Forwarder (Splunk syslog server) to collect these logs from Infinity Portal and then send them to a Splunk Enterprise Security SAAS ?&lt;/LI&gt;&lt;LI&gt;Do the the Infinity Portal implement (transparently) the CheckPoint Log EXPORTER sw module on its components?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Roby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 18:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193380#M235</guid>
      <dc:creator>roby198</dc:creator>
      <dc:date>2023-09-22T18:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193392#M236</link>
      <description>&lt;P&gt;Log Exporter runs on the Check Point management, not gateways.&lt;BR /&gt;In any case, it should be possible to set this up with Splunk, but only syslog format is supported per:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm#How" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm#How&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Which suggest you might need a Splunk syslog server.&lt;BR /&gt;Believe this can be confirmed through TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 22:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193392#M236</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-22T22:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193415#M237</link>
      <description>&lt;P&gt;My colleague and I did this for the customer couple of years back, will see if I can find the link about it here and send it over.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 14:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193415#M237</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-23T14:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193420#M238</link>
      <description>&lt;P&gt;Thank you Andy&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 18:29:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193420#M238</guid>
      <dc:creator>roby198</dc:creator>
      <dc:date>2023-09-23T18:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193421#M239</link>
      <description>&lt;P&gt;I believe this should help. Sorry for the delay, was out running, but I sure aint&amp;nbsp;&lt;SPAN&gt;Haile Gebrselassie &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Log-exporter-amp-Splunk-TLS/m-p/126164#M27609" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Log-exporter-amp-Splunk-TLS/m-p/126164#M27609&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 18:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193421#M239</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-23T18:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193422#M240</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The point 3 question "Do the the Infinity Portal implement (transparently) the CheckPoint Log EXPORTER sw module on its components" it is : the LOG EXPORTER is implemented on management.&lt;/P&gt;&lt;P&gt;And , could the management be on a customer on-premise and the logs flow to Infinity Portal datalake in cloud? correct?&lt;/P&gt;&lt;P&gt;About point 1, I believed that the syslog protocol already transported the information in the various proprietary SIEM formats.&lt;/P&gt;&lt;P&gt;About point 2,&amp;nbsp; I need Splunk Forwarder.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 18:45:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193422#M240</guid>
      <dc:creator>roby198</dc:creator>
      <dc:date>2023-09-23T18:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193423#M241</link>
      <description>&lt;P&gt;Point 3, correct.&lt;/P&gt;
&lt;P&gt;Point 1, yes, that is the case.&lt;/P&gt;
&lt;P&gt;Point 2, not 100% sure, but you may want to confirm with TAC.&lt;/P&gt;
&lt;P&gt;Example I gave you was that my colleague and I had TAC set up cp log export so logs from S1C (smart 1 cloud) would go to SIEM.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2023 18:52:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193423#M241</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-23T18:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193492#M242</link>
      <description>&lt;P&gt;Log Exporter runs on your Check Point management/log server.&lt;BR /&gt;If you're using Smart-1 Cloud or other services&amp;nbsp;via Infinity Portal, this is where Log Exporter functionality is implemented.&lt;BR /&gt;If you want to include events from your on-prem managed services in Infinity Portal, this can be done with&amp;nbsp;&lt;A href="https://www.checkpoint.com/horizon/events/" target="_self"&gt;Horizon Events&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 16:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193492#M242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-25T16:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193518#M243</link>
      <description>&lt;P&gt;Hi Andy , thank you so much, I'll follow the instructions in the link and i'll try it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Roby&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 19:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193518#M243</guid>
      <dc:creator>roby198</dc:creator>
      <dc:date>2023-09-25T19:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from Infinity Portal to Splunk</title>
      <link>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193519#M244</link>
      <description>&lt;P&gt;No worries mate. I sure hope it works.&lt;/P&gt;
&lt;P&gt;If any issues, let us know. Well, let us know the outcome either way : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 19:28:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193519#M244</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-25T19:28:55Z</dc:date>
    </item>
  </channel>
</rss>

