<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom syslog port in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183305#M33671</link>
    <description>&lt;P&gt;This is not what I'm after.&lt;/P&gt;
&lt;P&gt;That SK outlines how to 'How to configure Security Gateway on Gaia OS to send FireWall logs to an external Syslog server'.&lt;/P&gt;
&lt;P&gt;I'm already sending firewall logs from all gateways to remote log servers, and from there using log exporter to send in to Splunk.&lt;/P&gt;
&lt;P&gt;I'm referring specifically to configuring syslog on individual gateways to send Gaia system messages and audit events only to a remote syslog server. And we want to send this to the remote server on a custom port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's interesting that SK also states at the bottom of the document that the&amp;nbsp;fwsyslog_enable parameters is "is intended for optimization of logging performance in environments that require high log rates.Do&amp;nbsp;not&amp;nbsp;enable this kernel parameter unless explicitly instructed by Check Point Support.", as there is no mention of that in the&amp;nbsp;Logging and Monitoring R80.20 Administration Guide,&amp;nbsp;&amp;gt; Logging &amp;gt; Working with Syslog Servers section.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2023 04:44:04 GMT</pubDate>
    <dc:creator>Simon_Macpherso</dc:creator>
    <dc:date>2023-06-06T04:44:04Z</dc:date>
    <item>
      <title>Custom syslog port</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183302#M33669</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you please provide responses to the following syslog configuration related questions. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Is is possible to send syslog on a port other than the default UDP 514, possible by modifying configuration files /etc/syslog.conf or /etc/sysconfig/syslog? I have set up a remote syslog target which is listening on a different port. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Is it required to modify the fwsyslog_enable kernel parameter on each gateway to 1, to enable syslog. This is not specified in the r81.20 admin guide, however is it stated as a requirement in the r81.20 logging and monitoring admin guide.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 03:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183302#M33669</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-06-06T03:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Custom syslog port</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183303#M33670</link>
      <description>&lt;P&gt;The answer to both questions is here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk87560" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk87560&lt;/A&gt;&lt;BR /&gt;Looks like you can use a different port and you shouldn't use fwsyslog_enable unless TAC suggests it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 04:09:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183303#M33670</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-06T04:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Custom syslog port</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183305#M33671</link>
      <description>&lt;P&gt;This is not what I'm after.&lt;/P&gt;
&lt;P&gt;That SK outlines how to 'How to configure Security Gateway on Gaia OS to send FireWall logs to an external Syslog server'.&lt;/P&gt;
&lt;P&gt;I'm already sending firewall logs from all gateways to remote log servers, and from there using log exporter to send in to Splunk.&lt;/P&gt;
&lt;P&gt;I'm referring specifically to configuring syslog on individual gateways to send Gaia system messages and audit events only to a remote syslog server. And we want to send this to the remote server on a custom port.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's interesting that SK also states at the bottom of the document that the&amp;nbsp;fwsyslog_enable parameters is "is intended for optimization of logging performance in environments that require high log rates.Do&amp;nbsp;not&amp;nbsp;enable this kernel parameter unless explicitly instructed by Check Point Support.", as there is no mention of that in the&amp;nbsp;Logging and Monitoring R80.20 Administration Guide,&amp;nbsp;&amp;gt; Logging &amp;gt; Working with Syslog Servers section.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 04:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183305#M33671</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-06-06T04:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Custom syslog port</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183308#M33673</link>
      <description>&lt;P&gt;Got an answer from TAC. There is no way to change the default so I've had to NAT the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 06:24:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183308#M33673</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-06-06T06:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom syslog port</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183366#M33675</link>
      <description>&lt;P&gt;Ah yes, that's a beast of a different color.&lt;BR /&gt;You might be able to make the relevant change in /etc/rsyslog.conf and make the file immutable so the OS doesn't overwrite it.&lt;BR /&gt;However, that falls into "unsupported" category.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 19:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-syslog-port/m-p/183366#M33675</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-06T19:23:59Z</dc:date>
    </item>
  </channel>
</rss>

