<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set syslog severity grade log send to syslog server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16871#M1273</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has syslog restarted since this configuration took place?&lt;/P&gt;&lt;P&gt;I believe syslogd should automatically restart anytime you change the configuration, but it's helpful to double-check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Nov 2018 19:28:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-11-16T19:28:59Z</dc:date>
    <item>
      <title>How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16870#M1272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the title, I have set as&amp;nbsp;sk92798&lt;/P&gt;&lt;P&gt;add syslog log-remote-address 172.22.112.119 level emerg &lt;BR /&gt;set syslog filename /var/log/messages &lt;BR /&gt;set syslog cplogs off &lt;BR /&gt;set syslog mgmtauditlogs on &lt;BR /&gt;set syslog auditlog permanent &lt;BR /&gt;set syslog uncompressmessages off &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@demoCP:0]# clock&lt;BR /&gt;Fri Nov 16 13:00:42 2018 -0.152526 seconds&lt;BR /&gt;[Expert@demoCP:0]# cat /etc/syslog.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/syslog_xlate on Fri Nov 16 12:00:40 2018&lt;BR /&gt;# &lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;# &lt;BR /&gt;auth.* /var/log/auth&lt;BR /&gt;mail.* -/var/log/maillog&lt;BR /&gt;cron.* -/var/log/cron&lt;BR /&gt;*.info;local5.emerg;local0.notice;authpriv.emerg;cron.emerg;mail.emerg /var/log/messages&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#*.info;local5.none;local0.notice;authpriv.none;cron.none;mail.none /var/log/messages&lt;BR /&gt;#*.info;local5.none;local0.notice;authpriv.none;cron.none;mail.none /var/log/messages&lt;/P&gt;&lt;P&gt;#*.debug;local5.debug;local0.debug;authpriv.debug;cron.debug;mail.debug /var/log/messages&lt;/P&gt;&lt;P&gt;#*.info;local5.info;local0.info;authpriv.info;cron.info;mail.info /var/log/messages&lt;/P&gt;&lt;P&gt;#*.notice;local5.notice;local0.notice;authpriv.notice;cron.notice;mail.notice /var/log/messages&lt;BR /&gt;*.emerg *&lt;BR /&gt;*.emerg @172.22.112.119&lt;BR /&gt;local7.* /var/log/boot.log&lt;BR /&gt;authpriv.* /var/log/secure&lt;BR /&gt;uucp.crit;news.crit /var/log/spooler&lt;BR /&gt;[Expert@demoCP:0]# clock&lt;BR /&gt;Fri Nov 16 13:01:06 2018 -0.164737 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but I can see notice syslog send to syslog server. What is wrong with it ?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 05:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16870#M1272</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2018-11-16T05:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16871#M1273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has syslog restarted since this configuration took place?&lt;/P&gt;&lt;P&gt;I believe syslogd should automatically restart anytime you change the configuration, but it's helpful to double-check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:28:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16871#M1273</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-16T19:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16872#M1274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Off course, service restart but it didn't seem useful. Meanwhile, I found if I annotating all code in&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;/etc/syslog.conf. CP will send notice logs to Syslog server. I had config as &lt;SPAN style="font-weight: normal; font-size: 14px;"&gt;sk87560 and&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;sk92798.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;So, any step can exclude traffic logs? The client just wants to save simple and indicate clear log.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 00:02:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16872#M1274</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2018-11-17T00:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16873#M1275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"If I annotating all code in /etc/syslog.conf" what does this mean?&lt;/P&gt;&lt;P&gt;What do you mean "traffic logs"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're talking about stuff that would normally appear in Logs/Reporting or SmartView, this stuff does not go to syslog unless you're running Log Exporter or similar and even then, it shouldn't go to the system syslog (unless you've configured it to).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 00:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16873#M1275</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-17T00:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16874#M1276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;"If I annotating all code in /etc/syslog.conf" what does this mean?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;&lt;SPAN&gt;/etc/syslog.conf is syslog&amp;nbsp;cofig file.&amp;nbsp;&lt;/SPAN&gt;I think it should do not override any logs to&amp;nbsp;dedicate file. So, I think it should other CP software&amp;nbsp;&lt;SPAN style="color: #2e3033; background-color: #f9fbfc; font-weight: 200;"&gt;component&lt;/SPAN&gt; send logs to Syslog&amp;nbsp;server. I had check linux syslog config, config&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;/etc/syslog.conf to control syslog. Pls confirm&amp;nbsp;any errors to &lt;SPAN style="color: #2e3033; background-color: #f9fbfc; font-weight: 200;"&gt;Implementation requirement&amp;nbsp;&lt;/SPAN&gt;used&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;sk87560 and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; font-size: 14px;"&gt;sk92798. Or anything else mistakes.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; color: #000000; font-size: 14px;"&gt;What do you mean "traffic logs"?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; color: #000000; font-size: 14px;"&gt;Detail as the&amp;nbsp;attachment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; border: 0px; color: #000000; font-size: 14px;"&gt;The client config CP send logs to Splunk. You know Splunk pays as flow rate. So, he didn't want to too many low &lt;SPAN style="background-color: #ffffff;"&gt;severity logs send to it.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 00:41:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16874#M1276</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2018-11-17T00:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16875#M1277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you configure the gateway to send&amp;nbsp;Firewall blade logs via syslog as&amp;nbsp;described in sk87560, they are &lt;EM&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/EM&gt; sent via syslogd.&lt;/P&gt;&lt;P&gt;The configuration of /etc/syslogd.conf is therefore irrelevant in this case.&lt;/P&gt;&lt;P&gt;There is no mechanism to filter what logs are sent: it's either all Firewall blade logs or nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, the method described in sk87560 only sends Firewall blade logs and not logs from other Software Blades.&lt;/P&gt;&lt;P&gt;For other blades, you should use &lt;A href="https://community.checkpoint.com/message/16349"&gt;Log Exporter guide&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log Exporter currently doesn't support filtering logs either&amp;nbsp;(other than filtering out Firewall blade logs) but I believe we plan to add this&amp;nbsp;to Log Exporter in the future.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 01:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16875#M1277</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-17T01:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16876#M1278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Em.............So,&amp;nbsp;could you pls describe&amp;nbsp;when will suitable for&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;sk92798? Does&amp;nbsp;&lt;SPAN&gt;sk92798 only used in local disk?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 01:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16876#M1278</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2018-11-17T01:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16877#M1279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk92798 is only relevant for events that originate from the Gaia OS itself, i.e. things that would normally appear in /var/log/messages.&lt;/P&gt;&lt;P&gt;Some/all of these events can be forwarded to an external syslog server, depending on how you implement sk92798.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 01:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16877#M1279</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-17T01:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to set syslog severity grade log send to syslog server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16878#M1280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All right. Understand. THX!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 02:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-set-syslog-severity-grade-log-send-to-syslog-server/m-p/16878#M1280</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2018-11-17T02:12:30Z</dc:date>
    </item>
  </channel>
</rss>

