<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exporting logs from custom threat intelligence in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114194#M15967</link>
    <description>&lt;P&gt;I have not seen any information regarding custom intel feeds through management API, only ioc_feed in article&amp;nbsp;&lt;SPAN&gt;sk132193. However that being said, I have the feed already ingesting through ioc_feeds and am now looking to report back to a logging server via cp_export_log (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank"&gt;Log Exporter - Check Point Log Export&lt;/A&gt;). Really just need any assistance on defining how to filter the cp_export_log to only export on events where an IOC from ioc_feed has been seen. Cheers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Mar 2021 05:31:54 GMT</pubDate>
    <dc:creator>sandman</dc:creator>
    <dc:date>2021-03-22T05:31:54Z</dc:date>
    <item>
      <title>Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114181#M15959</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I am configuring the importing of custom threat intelligence feeds into the R80.40 checkpoint security gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to configure exporting of specific events to a external syslog server.&lt;/P&gt;&lt;P&gt;If an IOC from from custom threat intelligence feed is seen, I would like the associated event/log sent for this indicator sent to an external syslog server/collector.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand it is possible to send filtered logs to an external syslog server, however I am unsure of the ids/identifiers for the custom threat intelligence feed logs to filter on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to do this?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 22:37:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114181#M15959</guid>
      <dc:creator>sandman</dc:creator>
      <dc:date>2021-03-21T22:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114183#M15960</link>
      <description>&lt;P&gt;How precisely are you importing the IoCs?&lt;BR /&gt;In any case, IoCs are blocked with either Anti-Virus or Anti-Bot.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 00:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114183#M15960</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-22T00:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114184#M15964</link>
      <description>&lt;P&gt;Hi there PhoneBoy,&lt;/P&gt;&lt;P&gt;Unsure what you mean by "How precisely". I am using multiple custom intelligence "ioc_feeds add" commands to pull different IOC types via an API through https from one threat intelligence provider. The organisation who provides the feeds requires reporting on what IOCs from their feed are seen by the checkpoint.&lt;/P&gt;&lt;P&gt;Is it possible to send logs (from Anti-virus/Anti-bot blades?) to an external syslog server relating to the custom ioc feed IOCSs being seen?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 01:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114184#M15964</guid>
      <dc:creator>sandman</dc:creator>
      <dc:date>2021-03-22T01:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114186#M15965</link>
      <description>&lt;P&gt;You can also define IoCs via the management APIs, which is different than importing them via ioc_feeds.&lt;/P&gt;
&lt;P&gt;Each indicator should have a unique name associated with it.&lt;BR /&gt;Offhand, I don't remember exactly what field it shows up in.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8166"&gt;@TP_Master&lt;/a&gt;&amp;nbsp;do you happen to know?&lt;/P&gt;
&lt;P&gt;I would think you could filter based on that (or at the very least the blades used).&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 02:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114186#M15965</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-22T02:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114194#M15967</link>
      <description>&lt;P&gt;I have not seen any information regarding custom intel feeds through management API, only ioc_feed in article&amp;nbsp;&lt;SPAN&gt;sk132193. However that being said, I have the feed already ingesting through ioc_feeds and am now looking to report back to a logging server via cp_export_log (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank"&gt;Log Exporter - Check Point Log Export&lt;/A&gt;). Really just need any assistance on defining how to filter the cp_export_log to only export on events where an IOC from ioc_feed has been seen. Cheers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 05:31:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114194#M15967</guid>
      <dc:creator>sandman</dc:creator>
      <dc:date>2021-03-22T05:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114403#M15997</link>
      <description>&lt;P&gt;Hi there&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;, did you or anyone manage to find out info to be used in "cp_export_log" command&amp;nbsp; to send events relating to and ioc_feeds being seen?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 20:47:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114403#M15997</guid>
      <dc:creator>sandman</dc:creator>
      <dc:date>2021-03-23T20:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting logs from custom threat intelligence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114405#M15998</link>
      <description>&lt;P&gt;Nothing that specifically covers this.&lt;BR /&gt;The approach I would take to find out is to see what log field(s) contain information related to the IoCs (mostly likely the “unique name” of the IoC, as noted in the IoC file).&lt;BR /&gt;Then you should be able to filter based on the contents of that field and the blades I mentioned.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 21:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-logs-from-custom-threat-intelligence/m-p/114405#M15998</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-23T21:16:57Z</dc:date>
    </item>
  </channel>
</rss>

