<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog messages from the Security Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31766#M24880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to receive syslog messages from the security gateway itself (not traffic related logs), for example, /var/log/messages from syslog. The issue is that, if you activate the syslog from the security gateway, the syslog messages are not in RFC compatible format, which screws the parsing on the server side.&lt;/P&gt;&lt;P&gt;I've been thinking about using the "send traffic to the Management Server" option and export (or view) the logs from there to the syslog server.&lt;/P&gt;&lt;P&gt;What is the best course of action to achieve logging to an external server? What is usually used on these situations?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 16 Jun 2018 17:26:27 GMT</pubDate>
    <dc:creator>Tiago_Cerqueira</dc:creator>
    <dc:date>2018-06-16T17:26:27Z</dc:date>
    <item>
      <title>Syslog messages from the Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31766#M24880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to receive syslog messages from the security gateway itself (not traffic related logs), for example, /var/log/messages from syslog. The issue is that, if you activate the syslog from the security gateway, the syslog messages are not in RFC compatible format, which screws the parsing on the server side.&lt;/P&gt;&lt;P&gt;I've been thinking about using the "send traffic to the Management Server" option and export (or view) the logs from there to the syslog server.&lt;/P&gt;&lt;P&gt;What is the best course of action to achieve logging to an external server? What is usually used on these situations?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Jun 2018 17:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31766#M24880</guid>
      <dc:creator>Tiago_Cerqueira</dc:creator>
      <dc:date>2018-06-16T17:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog messages from the Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31767#M24881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "Send Traffic to the Management Server" options puts those logs in the same place you see your traffic logs.&lt;/P&gt;&lt;P&gt;Those, of course, can be exported from there with Log Exporter just like the traffic logs.&lt;/P&gt;&lt;P&gt;However, I don't know that it changes the format of the log entries any.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2018 02:40:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31767#M24881</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-17T02:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog messages from the Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31768#M24882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure gateways to send logs directly to syslog servers. Checkpoint supports RFC 3164 and RFC 5424. Can you share a sample of syslog messages that could not parse on the syslog server.&lt;/P&gt;&lt;P&gt;"Sending traffic to management server" is a good option, after enabling this you will able to see firewall traffic related logs and system messages together. I would not export it to additional syslog server,&amp;nbsp;you can see both logs in management server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jun 2018 05:15:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31768#M24882</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-17T05:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog messages from the Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31769#M24883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Huseyin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue we're having is that the messages are missing the hostname, timestamp, and syslog protocol version. This has been previously described under&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk100727.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;We were investigating if it was a viable option to export the logs to the management server and export them out to an external syslog and parse it there, since they are exported in CEF format and that would allow us to parse the events.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;We are on R80.10 (with some install base on R77.30, to be brought to R80.10 in the next few months).&amp;nbsp;We are not looking to install the hotfix described in the SK, as it will require extra maintainability, as well as introducing potentially less stable code on the chassis.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 05:47:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/31769#M24883</guid>
      <dc:creator>Tiago_Cerqueira</dc:creator>
      <dc:date>2018-06-18T05:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog messages from the Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/151609#M24884</link>
      <description>&lt;P&gt;poignant sarcasm on {&lt;/P&gt;&lt;P&gt;Meanwhile there is a fixed version R81 from take 34 (36), where this is inkluded. Only 12 years after the RFC has been "modernized" and 7 years after this has been mentioned in sk&lt;SPAN&gt;100727&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;} poignant sarkassm off&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:15:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Syslog-messages-from-the-Security-Gateway/m-p/151609#M24884</guid>
      <dc:creator>CarstenWeber</dc:creator>
      <dc:date>2022-06-23T14:15:15Z</dc:date>
    </item>
  </channel>
</rss>

