<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export logs from var / log / messages in cef format in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201317#M37851</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your answer, but since from the gateways I can send syslog messages directly to other syslog servers apart the manager I imagined I could send them directly in CEF format.&lt;/P&gt;&lt;P&gt;One further question if you can help.&lt;/P&gt;&lt;P&gt;I managed to configure the manager to send in CEF format, mas the amount of information is huge, and I dont see no changes either I configure it to send all messages or just emergency.&lt;/P&gt;&lt;P&gt;Is there a way to configure the CEF level of messages?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 21 Dec 2023 15:31:55 GMT</pubDate>
    <dc:creator>CarlosDias</dc:creator>
    <dc:date>2023-12-21T15:31:55Z</dc:date>
    <item>
      <title>Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132678#M19679</link>
      <description>&lt;PRE&gt;&lt;SPAN class=""&gt;hello, is it possible to export logs from / var / log / messages in cef format to siem system?
It is known that it is not possible to do it through cp_log_export, and with sk102995 there is no way to change the format to cef.&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Oct 2021 06:44:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132678#M19679</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2021-10-27T06:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132681#M19680</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=Basic&amp;amp;product=SmartEvent" target="_blank"&gt;sk122323: Log Exporter - Check Point Log Export&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Formats:&lt;/STRONG&gt;&lt;SPAN&gt; Syslog, Splunk, CEF, LEEF, Generic, JSON, LogRhythm, RSA&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;CODE&gt;cp_log_export add name &amp;lt;&lt;EM&gt;Name&lt;/EM&gt;&amp;gt; [domain-server &amp;lt;&lt;EM&gt;Name or IP address of Domain Server&lt;/EM&gt;&amp;gt;] target-server &amp;lt;&lt;EM&gt;HostName or IP address of Target Server&lt;/EM&gt;&amp;gt; target-port &amp;lt;&lt;EM&gt;Port on Target Server&lt;/EM&gt;&amp;gt; protocol {udp | tcp} format {syslog | splunk |&amp;nbsp;cef | leef | generic | json | logrhythm | rsa}&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 07:04:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132681#M19680</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-27T07:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132682#M19681</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, I looked at this sk, there is no way to export specifically / var / log / messages, the manufacturer says the same&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 07:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132682#M19681</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2021-10-27T07:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132692#M19687</link>
      <description>&lt;P&gt;Look into this discussion about getting logs from&amp;nbsp;&lt;SPAN&gt;security gateway (not traffic related logs, but for example, /var/log/messages) from syslog:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Syslog-messages-from-the-Security-Gateway/td-p/31766" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Syslog-messages-from-the-Security-Gateway/td-p/31766&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 08:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132692#M19687</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-27T08:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132712#M19692</link>
      <description>&lt;P&gt;Log Exporter can export Security Logs (not from /var/log/messages) in CEF format.&lt;BR /&gt;You can send OS logs to the Security Logs as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;mentions, which can then be exported as CEF.&lt;BR /&gt;However, I suspect the result of that may not be what you’re after.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 13:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/132712#M19692</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-27T13:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201273#M37844</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am running R81.10 JHF 110 and only see this command on the Manager.&lt;/P&gt;&lt;P&gt;What about the Gateways?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 11:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201273#M37844</guid>
      <dc:creator>CarlosDias</dc:creator>
      <dc:date>2023-12-21T11:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201297#M37848</link>
      <description>&lt;P&gt;Firewall logs are sent to the manager or log host. Therefore this command is mangement/logserver only.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 13:32:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201297#M37848</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-12-21T13:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Export logs from var / log / messages in cef format</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201317#M37851</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your answer, but since from the gateways I can send syslog messages directly to other syslog servers apart the manager I imagined I could send them directly in CEF format.&lt;/P&gt;&lt;P&gt;One further question if you can help.&lt;/P&gt;&lt;P&gt;I managed to configure the manager to send in CEF format, mas the amount of information is huge, and I dont see no changes either I configure it to send all messages or just emergency.&lt;/P&gt;&lt;P&gt;Is there a way to configure the CEF level of messages?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 15:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-logs-from-var-log-messages-in-cef-format/m-p/201317#M37851</guid>
      <dc:creator>CarlosDias</dc:creator>
      <dc:date>2023-12-21T15:31:55Z</dc:date>
    </item>
  </channel>
</rss>

