<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CP GW syslog configuration question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156946#M27188</link>
    <description>&lt;P&gt;Like I said, the logs will show in exactly the same place your Access and Threat Prevention logs will show, which is not /var/log/messages.&lt;BR /&gt;In my experience, the OS logs won’t appear to be very useful when viewed in SmartConsole/SmartView.&lt;BR /&gt;Possible they may be more useful if you write a parser for said logs, but we don’t provide one for that purpose by default.&lt;/P&gt;
&lt;P&gt;If your goal is to collect the OS syslogs centrally, all devices should send their syslogs directly to your collector and not have them sent to your management.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2022 19:18:39 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-09-09T19:18:39Z</dc:date>
    <item>
      <title>CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156917#M27175</link>
      <description>&lt;P&gt;YK-FW-A&amp;gt; show configuration syslog&lt;BR /&gt;add syslog log-remote-address 2.2.2.2 level all&lt;BR /&gt;set syslog filename /var/log/messages&lt;BR /&gt;set syslog cplogs on&lt;BR /&gt;set syslog mgmtauditlogs on&lt;BR /&gt;set syslog auditlog permanent&lt;BR /&gt;set syslog uncompressmessages off&lt;/P&gt;&lt;P&gt;YK-FW-A&amp;gt; show syslog all&lt;BR /&gt;Syslog Parameters:&lt;BR /&gt;Remote Address 2.2.2.2&lt;BR /&gt;Levels all&lt;BR /&gt;Auditlog permanent&lt;BR /&gt;Destination Log Filename /var/log/messages&lt;BR /&gt;YK-FW-A&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="微信截图_20220909202925.png" style="width: 821px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17728i0C5C4D8B3F6E0060/image-size/large?v=v2&amp;amp;px=999" role="button" title="微信截图_20220909202925.png" alt="微信截图_20220909202925.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I can see GW&amp;nbsp; written some logs into /var/log/message, but still can not find any GW syslogs written in the SMS /var/log/message file. Who can give me some ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:33:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156917#M27175</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-09-09T12:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156919#M27176</link>
      <description>&lt;P&gt;“Accept Syslog Messages” means the SMS can be a target of syslog messages from other devices.&lt;BR /&gt;Those logs will not appear in /var/log/messages on the SMS but in with SmartView similar to Access/Threat Prevention.&lt;BR /&gt;Unless you have parsers written for the messages, they may not appear in a very useful format.&lt;/P&gt;
&lt;P&gt;Please describe what your ultimate goal is.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156919#M27176</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-09T12:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156920#M27177</link>
      <description>&lt;P&gt;YK-FW-A&amp;gt; show configuration syslog&lt;BR /&gt;add syslog log-remote-address 2.2.2.2 level all&lt;BR /&gt;set syslog filename /var/log/messages&lt;BR /&gt;set syslog cplogs on&lt;BR /&gt;set syslog mgmtauditlogs on&lt;BR /&gt;set syslog auditlog permanent&lt;BR /&gt;set syslog uncompressmessages off&lt;/P&gt;&lt;P&gt;YK-FW-A&amp;gt; show syslog all&lt;BR /&gt;Syslog Parameters:&lt;BR /&gt;Remote Address 2.2.2.2&lt;BR /&gt;Levels all&lt;BR /&gt;Auditlog permanent&lt;BR /&gt;Destination Log Filename /var/log/messages&lt;BR /&gt;YK-FW-A&amp;gt;&lt;/P&gt;&lt;P&gt;The ultimate goal is sending local GW system logs(like account log in/ log out) to the SMS&amp;nbsp; and Syslog server storage.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156920#M27177</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-09-09T12:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156923#M27178</link>
      <description>&lt;P&gt;When you say “to the SMS” where precisely do you expect to see the syslog messages appear?&lt;BR /&gt;If you expect gateway syslogs to be sent to /var/log/messages on the SMS, that’s not how “Accept Syslog Messages” works and is probably not what you want.&lt;/P&gt;
&lt;P&gt;What is precisely meant by “syslog server storage.”&lt;BR /&gt;That sounds like an external (not gateway, not SMS) device…what exactly is it?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 12:59:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156923#M27178</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-09T12:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156927#M27180</link>
      <description>&lt;P&gt;When you say “to the SMS” where precisely do you expect to see the syslog messages appear?&lt;BR /&gt;-----&amp;gt;Yes&lt;BR /&gt;If you expect gateway syslogs to be sent to /var/log/messages on the SMS, that’s not how “Accept Syslog Messages” works and is probably not what you want.&lt;BR /&gt;-----&amp;gt;Oh, so where is“Accept Syslog Messages”used?&lt;BR /&gt;What is precisely meant by “syslog server storage.”&lt;BR /&gt;That sounds like an external (not gateway, not SMS) device…what exactly is it?&lt;BR /&gt;-----&amp;gt;Yes, I mean an external device.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 13:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156927#M27180</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-09-09T13:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: CP GW syslog configuration question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156946#M27188</link>
      <description>&lt;P&gt;Like I said, the logs will show in exactly the same place your Access and Threat Prevention logs will show, which is not /var/log/messages.&lt;BR /&gt;In my experience, the OS logs won’t appear to be very useful when viewed in SmartConsole/SmartView.&lt;BR /&gt;Possible they may be more useful if you write a parser for said logs, but we don’t provide one for that purpose by default.&lt;/P&gt;
&lt;P&gt;If your goal is to collect the OS syslogs centrally, all devices should send their syslogs directly to your collector and not have them sent to your management.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 19:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-GW-syslog-configuration-question/m-p/156946#M27188</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-09T19:18:39Z</dc:date>
    </item>
  </channel>
</rss>

