<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is best practice for syslog sending in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169870#M30793</link>
    <description>&lt;P&gt;Regarding Syslog for Security &amp;amp; Audit Logs the answer is:&lt;/P&gt;
&lt;P&gt;sk122323: Log Exporter - Check Point Log Export&lt;/P&gt;
&lt;P&gt;Weather you configure it in GAiA CLI or SmartConsole depends on the Management version &amp;amp; advanced nature of the config required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Syslog otherwise configured at the GAiA level is the system/OS logs as different to the above.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 08:39:10 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-02-01T08:39:10Z</dc:date>
    <item>
      <title>What is best practice for syslog sending</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169868#M30792</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We are setting a distributed environment&amp;nbsp;with two smart-1 appliances(MGMT-HA) and two quantum appliances(Cluster_XL).&lt;/P&gt;&lt;P&gt;We need to send syslog to other syslog server.&lt;/P&gt;&lt;P&gt;In this case, should I configure Gaia or Smartconsole to send syslogs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I want to know the difference between syslog that can be sent from Gaia and syslog that can be sent from smartconsole.&lt;/P&gt;&lt;P&gt;Please let me know if you have any information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:23:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169868#M30792</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2023-02-01T08:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: What is best practice for syslog sending</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169870#M30793</link>
      <description>&lt;P&gt;Regarding Syslog for Security &amp;amp; Audit Logs the answer is:&lt;/P&gt;
&lt;P&gt;sk122323: Log Exporter - Check Point Log Export&lt;/P&gt;
&lt;P&gt;Weather you configure it in GAiA CLI or SmartConsole depends on the Management version &amp;amp; advanced nature of the config required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Syslog otherwise configured at the GAiA level is the system/OS logs as different to the above.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:39:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169870#M30793</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-01T08:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is best practice for syslog sending</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169872#M30794</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;This SK is set to send syslog from smartconsole, but is checkpoint recommended to send it from smartconsole normally?&lt;BR /&gt;Gaia can also send syslogs, but when would you use this?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please let me know if you have any information.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 08:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169872#M30794</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2023-02-01T08:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: What is best practice for syslog sending</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169900#M30805</link>
      <description>&lt;P&gt;As above security logs come from management.&lt;/P&gt;
&lt;P&gt;Local OS events direct from the Gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 12:06:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169900#M30805</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-01T12:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is best practice for syslog sending</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169930#M30816</link>
      <description>&lt;P&gt;You would use it in Info level if you wanted to see DHCP assignments if the gateway is set to act as a DHCP server.&amp;nbsp; You can also scrub for local logins, and any critical or warnings you specifically need.&amp;nbsp; With PCI-DSS, sending these to your syslog servers allows better validation of their questions.&amp;nbsp; It is very satisfying during an audit to say, "Did you check on the syslog infrastructure?&amp;nbsp; It is there."&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-best-practice-for-syslog-sending/m-p/169930#M30816</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-02-01T14:19:41Z</dc:date>
    </item>
  </channel>
</rss>

