<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference on Harmony Endpoint Log Exporter vs Event Forwarding in Portal</title>
    <link>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/255000#M489</link>
    <description>&lt;P&gt;Yep, that is one of the main difference I noticed early on, though one thing we noticed is that there is a bit of format difference and naming convention from both but not all fields. There is also a big one we noticed where there is a long delay for forwarding logs to our syslog server for Event Forwarding. The first related log appeared on the Infinity Portal on 10:55:25 am yet Event Forwarding seems to have a delay in forwarding sometimes up to 15 minutes. Not sure if it's a region thing or intended behavior.&lt;/P&gt;&lt;P&gt;Top one is event forwarding, the other one is from log exporter&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug  7 11:05:53 20.73.193.110 1 2025-08-07T03:05:04.07Z Checkpoint eventforwarding-ac9290f2-f72f-4a1d-b6af-1244619f7a23 1650 - - {"time":"2025-08-07 02:56:10","id":"a4640108-dc71-f638-6894-161300000002","orig":"164.100.1.8","sequencenum":1,"action":"Prevent","i_f_dir":"inbound","policy_date":"2025-07-22T03:18:50Z","severity_int":3,"confidence_level_int":0,"protection_type":"URL Filtering","advanced_info":"\"exclusions\":[{\"exclusion_engine_type\":\"URL Filtering exclusions\",\"exclusion_type\":\"Domain\",\"exclusion_value\":{\"default_value\":\"www.yarenhost.com\",\"md5\":\"\",\"original_name\":\"\",\"signer\":\"\",\"process\":\"\",\"protection\":\"\",\"comment\":\"\"}}]","app_id":"0","app_properties":["Phishing, Low Risk"],"app_rule_id":" ","app_rule_name":" ","appi_name":"www.yarenhost.com","client_name":"Check Point Endpoint Security Client","client_version":["89.00.0430"],"description":"To exclude: Open the Harmony Management -&amp;gt; POLICY -&amp;gt; Threat Prevention -&amp;gt; EXCLUSION CENTER -&amp;gt; Web and Files Protection -&amp;gt; URL Filtering exclusions -&amp;gt; + -&amp;gt; paste this: www.yarenhost.com","dst":"0.0.0.0","event_type":"URLF Info Event","host_type":["Desktop"],"installed_products":"Firewall; Compliance; Application Control; Anti-Malware; VPN; Anti-Bot; Forensics; Threat Emulation","local_time":1754564170,"machine_guid":" ","matched_category":"Phishing","os_name":["Microsoft Windows 10 Home"],"os_version":["10.0-19045-SP0.0-SP"],"policy_name":"Default Anti-Bot settings","policy_number":3,"process_exe_path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe","product":"URL Filtering","product_family":"Endpoint","protection_name":"gen.urlf","reason":" ","resource":["https://www.yarenhost.com/"],"src":"192.168.237.165","src_machine_name":"DESKTOP-LDO9MC8","src_user_name":["fais"],"tenant_id":"REDACTED","user_name":" ","user_sid":"S-1-5-21-1451181116-1303984464-599200800-1001","usercheck_incident_uid":"3690ac7d","web_client_type":["Edge"],"domain":"SMC User","orig_log_server":"12c7035e-2b86-a94c-adcf-651a16d773de","orig_log_server_ip":"164.100.1.8","trimTime":"2025-08-07 02:56:00","trimHour":"2025-08-07 02:00:00","trimDate":"2025-08-07 00:00:00","hourOfDay":2,"severity":"High","confidence_level":"N/A","type":"Log","dedup_time":"2025-08-07 02:56:10.000001","__id":"2025-08-07 02:56:10_2025-08-07 02:56:10.000001"}&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Aug  7 10:57:04 52.210.248.134 1 2025-08-07T02:55:25Z i-0788aba73fdeed2a7 CheckPoint 31993 - [action:"Prevent"; flags:"131072"; ifdir:"inbound"; loguid:"{0x689415eb,0x0,0x80164a4,0x3e807cf9}"; origin:"164.100.1.8"; sequencenum:"1"; time:"1754535325"; version:"5"; __policy_id_tag:" "; advanced_info:"{\"exclusions\":[{\"exclusion_engine_type\":\"URL Filtering exclusions\",\"exclusion_type\":\"Domain\",\"exclusion_value\":{\"default_value\":\"www.yarenhost.com\",\"md5\":\"\",\"original_name\":\"\",\"signer\":\"\",\"process\":\"\",\"protection\":\"\",\"comment\":\"\"}}\]}"; app_id:"0"; app_properties:"Phishing, High Risk"; app_rule_id:" "; app_rule_name:" "; appi_name:"www.yarenhost.com"; client_name:"Check Point Endpoint Security Client"; client_version:"89.00.0430"; confidence_level:"N/A"; description:"To exclude: Open the Harmony Management -&amp;gt; POLICY -&amp;gt; Threat Prevention -&amp;gt; EXCLUSION CENTER -&amp;gt; Web and Files Protection -&amp;gt; URL Filtering exclusions -&amp;gt; + -&amp;gt; paste this: www.yarenhost.com"; dst:"0.0.0.0"; event_type:"URLF Info Event"; host_type:"Desktop"; installed_products:"Firewall; Compliance; Application Control; Anti-Malware; VPN; Anti-Bot; Forensics; Threat Emulation"; local_time:"1754564125"; machine_guid:" "; matched_category:"Phishing,High Risk"; os_name:"Microsoft Windows 10 Home"; os_version:"10.0-19045-SP0.0-SP"; policy_date:"1753154330"; policy_name:"Default Anti-Bot settings"; policy_number:"3"; process_exe_path:"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"; product:"URL Filtering"; product_family:"Endpoint"; protection_name:"gen.urlf"; protection_type:"URL Filtering"; reason:" "; resource:"https://www.yarenhost.com/"; severity:"3"; src:"192.168.237.165"; src_machine_name:"DESKTOP-LDO9MC8"; src_user_name:"fais"; tenant_id:"REDACTED"; user_name:" "; user_sid:"S-1-5-21-1451181116-1303984464-599200800-1001"; usercheck_incident_uid:"b694ea32"; web_client_type:"Edge"]​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Aug 2025 01:09:41 GMT</pubDate>
    <dc:creator>farisarch</dc:creator>
    <dc:date>2025-08-13T01:09:41Z</dc:date>
    <item>
      <title>Difference on Harmony Endpoint Log Exporter vs Event Forwarding</title>
      <link>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/254628#M487</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;Our team is currently building an in house SOC and utilizing events generated by Harmony Endpoint to feed the SIEM.&lt;/P&gt;&lt;P&gt;From what we have tested, there are two ways to send event logs from Harmony Endpoint to our SIEM which are:&lt;/P&gt;&lt;P&gt;1. Infinity Portal Event Forwarding&lt;/P&gt;&lt;P&gt;2. Harmony Endpoint Export Events or Log Exporter.&lt;/P&gt;&lt;P&gt;I've tried finding information on the difference of these two but there aren't many.&lt;/P&gt;&lt;P&gt;One that I notice is that Event Forwarding requires mTLS to be configured or you can't proceed, and there are no port restrictions during the configuration.&lt;/P&gt;&lt;P&gt;Log exporter has options whether to sent over port 514 or encrypted port 6514.&lt;/P&gt;&lt;P&gt;Other than that Event forwarding has options to create rules to forward services based on your needs.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 07:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/254628#M487</guid>
      <dc:creator>farisarch</dc:creator>
      <dc:date>2025-08-06T07:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Difference on Harmony Endpoint Log Exporter vs Event Forwarding</title>
      <link>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/254909#M488</link>
      <description>&lt;P&gt;The main difference, &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm" target="_self"&gt;at least from what I can see in the docs&lt;/A&gt;, is what data is forwarded (all services managed via Infinity Portal versus just the stuff for Harmony Endpoint).&lt;BR /&gt;Note that both of these features require a license (based on log volume).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 13:51:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/254909#M488</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-11T13:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Difference on Harmony Endpoint Log Exporter vs Event Forwarding</title>
      <link>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/255000#M489</link>
      <description>&lt;P&gt;Yep, that is one of the main difference I noticed early on, though one thing we noticed is that there is a bit of format difference and naming convention from both but not all fields. There is also a big one we noticed where there is a long delay for forwarding logs to our syslog server for Event Forwarding. The first related log appeared on the Infinity Portal on 10:55:25 am yet Event Forwarding seems to have a delay in forwarding sometimes up to 15 minutes. Not sure if it's a region thing or intended behavior.&lt;/P&gt;&lt;P&gt;Top one is event forwarding, the other one is from log exporter&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug  7 11:05:53 20.73.193.110 1 2025-08-07T03:05:04.07Z Checkpoint eventforwarding-ac9290f2-f72f-4a1d-b6af-1244619f7a23 1650 - - {"time":"2025-08-07 02:56:10","id":"a4640108-dc71-f638-6894-161300000002","orig":"164.100.1.8","sequencenum":1,"action":"Prevent","i_f_dir":"inbound","policy_date":"2025-07-22T03:18:50Z","severity_int":3,"confidence_level_int":0,"protection_type":"URL Filtering","advanced_info":"\"exclusions\":[{\"exclusion_engine_type\":\"URL Filtering exclusions\",\"exclusion_type\":\"Domain\",\"exclusion_value\":{\"default_value\":\"www.yarenhost.com\",\"md5\":\"\",\"original_name\":\"\",\"signer\":\"\",\"process\":\"\",\"protection\":\"\",\"comment\":\"\"}}]","app_id":"0","app_properties":["Phishing, Low Risk"],"app_rule_id":" ","app_rule_name":" ","appi_name":"www.yarenhost.com","client_name":"Check Point Endpoint Security Client","client_version":["89.00.0430"],"description":"To exclude: Open the Harmony Management -&amp;gt; POLICY -&amp;gt; Threat Prevention -&amp;gt; EXCLUSION CENTER -&amp;gt; Web and Files Protection -&amp;gt; URL Filtering exclusions -&amp;gt; + -&amp;gt; paste this: www.yarenhost.com","dst":"0.0.0.0","event_type":"URLF Info Event","host_type":["Desktop"],"installed_products":"Firewall; Compliance; Application Control; Anti-Malware; VPN; Anti-Bot; Forensics; Threat Emulation","local_time":1754564170,"machine_guid":" ","matched_category":"Phishing","os_name":["Microsoft Windows 10 Home"],"os_version":["10.0-19045-SP0.0-SP"],"policy_name":"Default Anti-Bot settings","policy_number":3,"process_exe_path":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe","product":"URL Filtering","product_family":"Endpoint","protection_name":"gen.urlf","reason":" ","resource":["https://www.yarenhost.com/"],"src":"192.168.237.165","src_machine_name":"DESKTOP-LDO9MC8","src_user_name":["fais"],"tenant_id":"REDACTED","user_name":" ","user_sid":"S-1-5-21-1451181116-1303984464-599200800-1001","usercheck_incident_uid":"3690ac7d","web_client_type":["Edge"],"domain":"SMC User","orig_log_server":"12c7035e-2b86-a94c-adcf-651a16d773de","orig_log_server_ip":"164.100.1.8","trimTime":"2025-08-07 02:56:00","trimHour":"2025-08-07 02:00:00","trimDate":"2025-08-07 00:00:00","hourOfDay":2,"severity":"High","confidence_level":"N/A","type":"Log","dedup_time":"2025-08-07 02:56:10.000001","__id":"2025-08-07 02:56:10_2025-08-07 02:56:10.000001"}&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Aug  7 10:57:04 52.210.248.134 1 2025-08-07T02:55:25Z i-0788aba73fdeed2a7 CheckPoint 31993 - [action:"Prevent"; flags:"131072"; ifdir:"inbound"; loguid:"{0x689415eb,0x0,0x80164a4,0x3e807cf9}"; origin:"164.100.1.8"; sequencenum:"1"; time:"1754535325"; version:"5"; __policy_id_tag:" "; advanced_info:"{\"exclusions\":[{\"exclusion_engine_type\":\"URL Filtering exclusions\",\"exclusion_type\":\"Domain\",\"exclusion_value\":{\"default_value\":\"www.yarenhost.com\",\"md5\":\"\",\"original_name\":\"\",\"signer\":\"\",\"process\":\"\",\"protection\":\"\",\"comment\":\"\"}}\]}"; app_id:"0"; app_properties:"Phishing, High Risk"; app_rule_id:" "; app_rule_name:" "; appi_name:"www.yarenhost.com"; client_name:"Check Point Endpoint Security Client"; client_version:"89.00.0430"; confidence_level:"N/A"; description:"To exclude: Open the Harmony Management -&amp;gt; POLICY -&amp;gt; Threat Prevention -&amp;gt; EXCLUSION CENTER -&amp;gt; Web and Files Protection -&amp;gt; URL Filtering exclusions -&amp;gt; + -&amp;gt; paste this: www.yarenhost.com"; dst:"0.0.0.0"; event_type:"URLF Info Event"; host_type:"Desktop"; installed_products:"Firewall; Compliance; Application Control; Anti-Malware; VPN; Anti-Bot; Forensics; Threat Emulation"; local_time:"1754564125"; machine_guid:" "; matched_category:"Phishing,High Risk"; os_name:"Microsoft Windows 10 Home"; os_version:"10.0-19045-SP0.0-SP"; policy_date:"1753154330"; policy_name:"Default Anti-Bot settings"; policy_number:"3"; process_exe_path:"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"; product:"URL Filtering"; product_family:"Endpoint"; protection_name:"gen.urlf"; protection_type:"URL Filtering"; reason:" "; resource:"https://www.yarenhost.com/"; severity:"3"; src:"192.168.237.165"; src_machine_name:"DESKTOP-LDO9MC8"; src_user_name:"fais"; tenant_id:"REDACTED"; user_name:" "; user_sid:"S-1-5-21-1451181116-1303984464-599200800-1001"; usercheck_incident_uid:"b694ea32"; web_client_type:"Edge"]​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 01:09:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/255000#M489</guid>
      <dc:creator>farisarch</dc:creator>
      <dc:date>2025-08-13T01:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Difference on Harmony Endpoint Log Exporter vs Event Forwarding</title>
      <link>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/255056#M490</link>
      <description>&lt;P&gt;If "events" are being sent, I imagine some time might be needed to ensure all data for that event is correlated, thus the delay.&lt;BR /&gt;It might also explain some differences in the logging.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2025 19:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Portal/Difference-on-Harmony-Endpoint-Log-Exporter-vs-Event-Forwarding/m-p/255056#M490</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-13T19:40:05Z</dc:date>
    </item>
  </channel>
</rss>

