<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending SIEM Mcafee logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182967#M33558</link>
    <description>&lt;DIV&gt;&lt;SPAN&gt;I see syn packages but not the syn/ack&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 01 Jun 2023 18:32:58 GMT</pubDate>
    <dc:creator>FabioLima1</dc:creator>
    <dc:date>2023-06-01T18:32:58Z</dc:date>
    <item>
      <title>Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182758#M33526</link>
      <description>&lt;P&gt;Hello everyone, everything good ? I need help.&lt;/P&gt;&lt;P&gt;I configured the log exporter but the events that arrive at the siem are very low, below the evidence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;name: LOG_EXP domain-server: : CK&lt;BR /&gt;enabled: true&lt;BR /&gt;target-server: 10.0.1.1&lt;BR /&gt;target-port: 514&lt;BR /&gt;protocol: udp&lt;BR /&gt;format: syslog&lt;BR /&gt;read-mode: raw&lt;BR /&gt;export-attachment-ids: false&lt;BR /&gt;export-link: false&lt;BR /&gt;export-attachment-link: false&lt;BR /&gt;time-in-milli: false&lt;BR /&gt;export-log-position: false&lt;BR /&gt;reconnect-interval: Not configured, using default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs&lt;/P&gt;&lt;P&gt;[4011834176][31 May 12:09:42] Files read rate [adtlog] : Current=0 Avg=0 MinAvg=0 Total=2 buffers (0/0/0/0)&lt;BR /&gt;[4028619584][31 May 12:09:47] Files read rate [log] : Current=0 Avg=0 MinAvg=0 Total=13 buffers (0/0/0/0)&lt;BR /&gt;[4028619584][31 May 12:09:47] Sent current: 0 average: 0 total: 0&lt;BR /&gt;[4011834176][31 May 12:09:47] Files read rate [adtlog] : Current=0 Avg=0 MinAvg=0 Total=2 buffers (0/0/0/0)&lt;BR /&gt;[4028619584][31 May 12:09:52] Files read rate [log] : Current=0 Avg=0 MinAvg=0 Total=13 buffers (0/0/0/0)&lt;BR /&gt;[4028619584][31 May 12:09:52] Sent current: 0 average: 0 total: 0&lt;BR /&gt;[4011834176][31 May 12:09:52] Files read rate [adtlog] : Current=0 Avg=0 MinAvg=0 Total=2 buffers (0/0/0/0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 15:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182758#M33526</guid>
      <dc:creator>FabioLima1</dc:creator>
      <dc:date>2023-05-31T15:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182834#M33537</link>
      <description>&lt;P&gt;What troubleshooting have you already done and which version and JHF is the Management in this case?&lt;/P&gt;
&lt;P&gt;Have you implemented any filters that we should be aware of?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 00:41:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182834#M33537</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-01T00:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182915#M33551</link>
      <description>&lt;P&gt;Version81.10 JHF 78&lt;/P&gt;&lt;P&gt;what I did for troubleshooting was to analyze the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 13:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182915#M33551</guid>
      <dc:creator>FabioLima1</dc:creator>
      <dc:date>2023-06-01T13:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182963#M33557</link>
      <description>&lt;P&gt;To be honest, I'm not sure what "evidence" you're showing here.&lt;BR /&gt;What precise commands generated this output or what precise logs did you pull this output from?&lt;/P&gt;
&lt;P&gt;Do you see traffic flowing to the destination syslog server with tcpdump?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 18:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182963#M33557</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T18:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182967#M33558</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;I see syn packages but not the syn/ack&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 01 Jun 2023 18:32:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182967#M33558</guid>
      <dc:creator>FabioLima1</dc:creator>
      <dc:date>2023-06-01T18:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182971#M33560</link>
      <description>&lt;P&gt;A SYN/ACK would come from the remote syslog server in this case.&lt;BR /&gt;If you're not getting that, it means there's a basic networking problem (either routing, a middle device blocking the traffic, or both).&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 19:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/182971#M33560</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T19:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183005#M33567</link>
      <description>&lt;P&gt;I made the change to use the sending using the udp protocol instead of tcp, now the Siem team informs me that the volume of logs is low&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 23:23:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183005#M33567</guid>
      <dc:creator>FabioLima1</dc:creator>
      <dc:date>2023-06-01T23:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183006#M33568</link>
      <description>&lt;P&gt;By what reasoning have your SIEM team concluded that "the volume of logs is low"?&lt;BR /&gt;Detailed comparisons of what's in SmartView versus the SIEM would need to be made starting from the moment logs started flowing via Log Exporter.&lt;BR /&gt;In general, the amount of logs sent by Log Exporter should be proportional to the current logs received on the logging server.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 23:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183006#M33568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T23:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183011#M33570</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71907"&gt;@FabioLima1&lt;/a&gt;&amp;nbsp;We definitely need more info here to be able to help you out better. When you indicate SIEM team told you volume of logs is low, Im not sure how to "digest" that info. Are they expecting to see certain amount of logs per minute/hour/day? Whatever you see as far as amount of logs on whatever log server it is, thats what should show up on SIEM side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use SIEM for few customers and so far, no issues as far as logs being received from the config we did in Smart-1 cloud environment.&lt;/P&gt;
&lt;P&gt;Again, maybe doing some basic packet captures may help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 02:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183011#M33570</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T02:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183066#M33591</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Were you able to look into things we mentioned?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 14:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183066#M33591</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T14:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183110#M33615</link>
      <description>&lt;P&gt;I did the capture and I see the logs going towards Siem. One question, I configured the export log in the MDS, can you tell me if the mds sends logs or only the cma and cml that forward the logs?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 19:33:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183110#M33615</guid>
      <dc:creator>FabioLima1</dc:creator>
      <dc:date>2023-06-02T19:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sending SIEM Mcafee logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183264#M33665</link>
      <description>&lt;P&gt;I don't believe configuring Log Exporter at the MDS level will export the logs from the various CMAs.&lt;BR /&gt;Each Domain would need to have Log Exporter configured on it.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 18:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-SIEM-Mcafee-logs/m-p/183264#M33665</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-05T18:00:43Z</dc:date>
    </item>
  </channel>
</rss>

