<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Integration with FortiSIEM solution in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226975#M43641</link>
    <description>&lt;P&gt;The sk given by Akos and Lesley is your best bet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 17 Sep 2024 18:11:14 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-17T18:11:14Z</dc:date>
    <item>
      <title>Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/87013#M6708</link>
      <description>&lt;P&gt;Hello members,&lt;/P&gt;&lt;P&gt;i have Checkpoint security firewall and would like to integrate it with FortiSIEM solution i need help as it is my first time to implement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 07:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/87013#M6708</guid>
      <dc:creator>FD</dc:creator>
      <dc:date>2020-06-02T07:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/87066#M6713</link>
      <description>&lt;P&gt;If it takes syslog, jsut use log exporter&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 13:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/87066#M6713</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-02T13:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/156749#M27048</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you manage to integrate the logs in fortisiem via Log exporter? Is the parser correct? Can you share the settings you used?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 12:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/156749#M27048</guid>
      <dc:creator>egas84</dc:creator>
      <dc:date>2022-09-07T12:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226966#M43636</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you share the settings to integrate with FortiSiem&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 16:42:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226966#M43636</guid>
      <dc:creator>peroskhan</dc:creator>
      <dc:date>2024-09-17T16:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226967#M43637</link>
      <description>&lt;P&gt;What do you mean under settings?&lt;/P&gt;
&lt;P&gt;This is the original SK:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk122323" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk122323&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can&amp;nbsp; setup based on your needs. Usually we send syslog to FortiSien, and the SIEM will parse the logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a look at in this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.fortinet.com/document/fortisiem/7.1.4/external-systems-configuration-guide/335430/check-point-firewall-1" target="_blank" rel="noopener"&gt;https://docs.fortinet.com/document/fortisiem/7.1.4/external-systems-configuration-guide/335430/check-point-firewall-1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You need to send syslog in CEF format according to this sample:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;cp_log_export add name &amp;lt;&lt;EM&gt;Name&lt;/EM&gt;&amp;gt; [domain-server {mds | all}] target-server &amp;lt;&lt;EM&gt;HostName or IP address of Target Server&lt;/EM&gt;&amp;gt; target-port &amp;lt;&lt;EM&gt;Port on Target Server&lt;/EM&gt;&amp;gt; protocol {udp | tcp} format {syslog | splunk |&amp;nbsp;cef | leef | generic | json | logrhythm | rsa} [&amp;lt;&lt;EM&gt;Optional Arguments&lt;/EM&gt;&amp;gt;]&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 17:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226967#M43637</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-17T17:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226968#M43638</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I use the following:&lt;BR /&gt;cp_log_export add name FortiSiem target-server x.x.x.x target-port 514 protocol udp format cef&lt;BR /&gt;cp_log_export restart name FortiSiem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 17:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226968#M43638</guid>
      <dc:creator>egas84</dc:creator>
      <dc:date>2024-09-17T17:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226974#M43640</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_LoggingAndMonitoring_AdminGuide/Topics-LMG/Log-Exporter-Configuration-in-SmartConsole.htm?tocpath=Log%20Exporter%7C_____2" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_LoggingAndMonitoring_AdminGuide/Topics-LMG/Log-Exporter-Configuration-in-SmartConsole.htm?tocpath=Log%20Exporter%7C_____2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Start with above and then:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk122323" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk122323&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Better to create object in SmartConsole. Before you always had to start from CLI but that changed and made it more easy. Still can do all via CLI but via GUI is better.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If all changes are done check with tcpdump if you see traffic being send out. tcpdump -nni any host IP port 514&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 18:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226974#M43640</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-17T18:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Integration with FortiSIEM solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226975#M43641</link>
      <description>&lt;P&gt;The sk given by Akos and Lesley is your best bet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 18:11:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Integration-with-FortiSIEM-solution/m-p/226975#M43641</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T18:11:14Z</dc:date>
    </item>
  </channel>
</rss>

