<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Audit Logs are not sent to SIEM when using dedicated log server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151541#M24827</link>
    <description>&lt;P&gt;The Log Server and the SMS should have different logs, thus there shouldn't be any overlap.&lt;BR /&gt;That said, I believe you can just configure Log Exporter to send audit logs.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 02:46:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-06-23T02:46:23Z</dc:date>
    <item>
      <title>Some Audit Logs are not sent to SIEM when using dedicated log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151384#M24711</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that some audit logs are sent to the siem while others aren't when using dedicated log servers, for example - if the operation is "Incident Viewed", "Set Object", "Delete Object", so basically the least important audit logs, then the Origin Log servers is the dedicated Log Server and the logs are sent to the SIEM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if the Operation is "Publish", "Delete Rule", "Create Rule" or "IPS Update" Than the Origin Log Server is usually the SMS itself and these audit logs are not being sent to the SIEM (as only the dedicated servers are sending the logs).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to send with log exporter all the audit logs to the siem even when using dedicated log servers, including those where the Origin log server IP is the SMS itself, as they contain info about important changes being made to IPS and access control configuration. How can that be done?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 17:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151384#M24711</guid>
      <dc:creator>AngeloP</dc:creator>
      <dc:date>2022-06-21T17:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Some Audit Logs are not sent to SIEM when using dedicated log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151402#M24720</link>
      <description>&lt;P&gt;I believe you can configure Log Exporter on the SMS in this case to export the relevant logs directly (assuming they are there).&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 21:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151402#M24720</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-21T21:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Some Audit Logs are not sent to SIEM when using dedicated log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151428#M24726</link>
      <description>&lt;P&gt;Thanks for the reply, so if I understand correctly, the log exporter should be configured both on the dedicated log servers and on the SMS, but the SMS should be configured to only send Audit logs in this case, as not to duplicate logs sent to the SIEM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a one liner command for log exporter to only export audit logs or does it require manipulation of the file&amp;nbsp;targetConfiguration.xml?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:53:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151428#M24726</guid>
      <dc:creator>AngeloP</dc:creator>
      <dc:date>2022-06-22T08:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Some Audit Logs are not sent to SIEM when using dedicated log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151541#M24827</link>
      <description>&lt;P&gt;The Log Server and the SMS should have different logs, thus there shouldn't be any overlap.&lt;BR /&gt;That said, I believe you can just configure Log Exporter to send audit logs.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 02:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Some-Audit-Logs-are-not-sent-to-SIEM-when-using-dedicated-log/m-p/151541#M24827</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-23T02:46:23Z</dc:date>
    </item>
  </channel>
</rss>

