<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262681#M59494</link>
    <description>&lt;P&gt;Of course man, never an issue, we are always here to help others.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Nov 2025 18:39:16 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-12T18:39:16Z</dc:date>
    <item>
      <title>[Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262321#M59472</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;I would like to know if it's possible to make changes to what can be sent to a SIEM server, similar to what is done in LogExporter, but using Smart-1 Cloud.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 13:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262321#M59472</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-10T13:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262407#M59473</link>
      <description>&lt;P&gt;As I recall, you have to modify some .xml and/or config files.&lt;BR /&gt;That would have to be handled by TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 01:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262407#M59473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-11-11T01:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262410#M59474</link>
      <description>&lt;P&gt;You can set it up from S1C portal. Will verify tomorrow and update you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 01:51:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262410#M59474</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T01:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262492#M59475</link>
      <description>&lt;P&gt;Hi the_rock&lt;/P&gt;&lt;P&gt;Thank you for your support. I wanted to see if this is possible because I want to improve the volume of events that the SIEM is receiving. I've only seen this in an on-premise management system, but I've never done it in the smart-1 cloud.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262492#M59475</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-11T13:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262493#M59476</link>
      <description>&lt;P&gt;Sorry mate, forgot to take a screenshot, give me 10-15 mins, will check it and update you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262493#M59476</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T13:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262495#M59477</link>
      <description>&lt;P&gt;Here it is.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262495#M59477</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T13:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262499#M59478</link>
      <description>&lt;P&gt;the_rock, I really appreciate your help.&lt;/P&gt;&lt;P&gt;But what I really need is to configure what should be sent.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;The SIEM is receiving these columns: origin, destination, port, blade, action, date and time.&lt;/P&gt;&lt;P&gt;I want to edit and send only the columns: origin, port, date and time.&lt;/P&gt;&lt;P&gt;In LogExporter I know we can edit a file (.xml), it has some limitations, but I know it's possible and I also wanted to know if this is possible in Smart-1 Cloud.&lt;/P&gt;&lt;P&gt;I apologize if I wasn't clear before.&lt;/P&gt;&lt;P&gt;I'll leave the link to the configuration I want to make, comparing it with LogExporter:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Log_Exporter/EN/Content/Topics/Filter-Configuration.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Log_Exporter/EN/Content/Topics/Filter-Configuration.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262499#M59478</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-11T13:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262501#M59479</link>
      <description>&lt;P&gt;K, got it! Then&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;was correct. Ask TAC once you open the case to check below file on backend and modify whats needed:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[Expert@CPHQVMFWMGT01:0]#&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[Expert@CPHQVMFWMGT01:0]# cd /opt/CPrt-R81.20/log_exporter/targets/&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[Expert@CPHQVMFWMGT01:0]# ls&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;CheckPointLogs&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[Expert@CPHQVMFWMGT01:0]# cd CheckPointLogs/&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;[Expert@CPHQVMFWMGT01:0]# vi targetConfiguration.xml&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:50:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262501#M59479</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T13:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262502#M59480</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/128536"&gt;@lucasfn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example from my lab:&lt;/P&gt;
&lt;P&gt;[Expert@CP-MANAGEMENT:0]# find / -name targetConfiguration.xml&lt;BR /&gt;/opt/CPrt-R82/log_exporter/targets/test-log/targetConfiguration.xml&lt;BR /&gt;/opt/CPrt-R82/log_exporter/targets/SentinelOne-XDR/targetConfiguration.xml&lt;BR /&gt;[Expert@CP-MANAGEMENT:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 13:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262502#M59480</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T13:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262569#M59481</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Let me know what fields you need changed and I can verify in my lab for you.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 01:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262569#M59481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T01:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262641#M59482</link>
      <description>&lt;P&gt;Hi the_rock,&lt;/P&gt;&lt;P&gt;Well, I'm still coordinating with the SIEM team on what they need from their side. But this is the information they've given me so far.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Header{&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; CEF:0| - log type - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check Point| - Vendor - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN-1 &amp;amp; FireWall-1| - Product - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check Point| - manufacturer - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Accept| - action - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; https| - protocol - necessary&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unknown| - accountname - não mencionado nos casos de uso, but it may be linked to cases of account manipulation and/or modification of rules or policies.&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;Body{&lt;BR /&gt;act=Accept - action - necessary&lt;BR /&gt;deviceDirection=0 - unknown - not mentioned in the use cases&lt;BR /&gt;rt=1762518075000 - timestamp - necessary&lt;BR /&gt;spt=30071 - necessary&lt;BR /&gt;dpt=443 - necessary&lt;BR /&gt;cs2Label=Rule Name&amp;nbsp; - necessary&lt;BR /&gt;cs2=Implied Rule&amp;nbsp; - necessary&lt;BR /&gt;layer_name=Policy_XX Network&amp;nbsp; - necessary&lt;BR /&gt;layer_uuid=32e912aa-dd67-4ba5-ad4e-2f122c69d987&amp;nbsp; - necessary&lt;BR /&gt;match_id=0 - unknown - not mentioned in the use cases&lt;BR /&gt;parent_rule=0 - unknown - not mentioned in the use cases&lt;BR /&gt;rule_action=Accept - necessary&lt;BR /&gt;rule_uid=0E3B6801-8AB0-4b1e-A317-8BE33055FB43&amp;nbsp; - necessary&lt;BR /&gt;ifname=DMZ - necessary&lt;BR /&gt;logid=0 - unknown - not mentioned in the use cases&lt;BR /&gt;loguid={0x462342d,0x62ac842e,0xbc016d08,0xb5efa7c3}&lt;BR /&gt;origin=x.x.x.x&amp;nbsp; - necessary&lt;BR /&gt;originsicname=CN\=FW-XX-1600,O\=Management_Service..cnupe4 - hostname and host domain - necessary&lt;BR /&gt;sequencenum=98 - unknown - not mentioned in the use cases&lt;BR /&gt;version=5 - unknown - not mentioned in the use cases&lt;BR /&gt;dst=x.x.x.x - necessary&lt;BR /&gt;inzone=External - necessary&lt;BR /&gt;outzone=Local - necessary&lt;BR /&gt;product=VPN-1 &amp;amp; FireWall-1 - necessary&lt;BR /&gt;proto=6 - unknown - not mentioned in the use cases&lt;BR /&gt;service_id=https - necessary&lt;BR /&gt;src=x.x.x.x - necessary&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 14:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262641#M59482</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-12T14:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262645#M59483</link>
      <description>&lt;P&gt;Here is what it looks like in my lab:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-MANAGEMENT:0]# more /opt/CPrt-R82/log_exporter/targets/SentinelOne-XDR/targetConfiguration.xml&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="utf-8"?&amp;gt;&lt;BR /&gt;&amp;lt;export id="targetObjectUID"&amp;gt;&amp;lt;!--object uuid!--&amp;gt;&lt;BR /&gt;&amp;lt;version&amp;gt;9&amp;lt;/version&amp;gt; &amp;lt;!-- Version of this file--&amp;gt;&lt;BR /&gt;&amp;lt;is_enabled&amp;gt;true&amp;lt;/is_enabled&amp;gt;&amp;lt;!--Is the process allowed to run, and start on cpstart--&amp;gt;&lt;BR /&gt;&amp;lt;!-- Destination section defines the properties of the export target --&amp;gt;&lt;BR /&gt;&amp;lt;destination type="syslog"&amp;gt; &amp;lt;!-- Target output type --&amp;gt;&lt;BR /&gt;&amp;lt;ip&amp;gt;172.16.10.108&amp;lt;/ip&amp;gt;&amp;lt;!--the ip of the syslog server--&amp;gt;&lt;BR /&gt;&amp;lt;port&amp;gt;8002&amp;lt;/port&amp;gt;&amp;lt;!--the port on which the syslog is listening to--&amp;gt;&lt;BR /&gt;&amp;lt;protocol&amp;gt;udp&amp;lt;/protocol&amp;gt;&amp;lt;!--udp/tcp--&amp;gt;&lt;BR /&gt;&amp;lt;local_addr_ip&amp;gt;&amp;lt;/local_addr_ip&amp;gt;&amp;lt;!--local address ip--&amp;gt;&lt;BR /&gt;&amp;lt;!--the configuration of tls--&amp;gt;&lt;BR /&gt;&amp;lt;transport&amp;gt;&lt;BR /&gt;&amp;lt;security&amp;gt;&amp;lt;/security&amp;gt;&amp;lt;!--clear/tls--&amp;gt;&lt;BR /&gt;&amp;lt;!-- the following section is relevant only if &amp;lt;security&amp;gt; is tls --&amp;gt;&lt;BR /&gt;&amp;lt;pem_ca_file&amp;gt;&amp;lt;/pem_ca_file&amp;gt;&lt;BR /&gt;&amp;lt;p12_certificate_file&amp;gt;&amp;lt;/p12_certificate_file&amp;gt;&lt;BR /&gt;&amp;lt;client_certificate_challenge_phrase&amp;gt;&amp;lt;/client_certificate_challenge_phrase&amp;gt;&lt;BR /&gt;&amp;lt;/transport&amp;gt;&lt;BR /&gt;&amp;lt;reconnect_interval&amp;gt;&amp;lt;/reconnect_interval&amp;gt;&amp;lt;!-- Shedule reconnection to the destination server (empty to disable [defa&lt;BR /&gt;ult] | number of minutes) --&amp;gt;&lt;BR /&gt;&amp;lt;/destination&amp;gt;&lt;BR /&gt;&amp;lt;!-- Enrichment configuration, exporting domain server name, orig_log_server uuid and orig_log_server ip --&amp;gt;&lt;BR /&gt;&amp;lt;data_enrichment&amp;gt;&lt;BR /&gt;&amp;lt;export_domain&amp;gt;false&amp;lt;/export_domain&amp;gt;&lt;BR /&gt;&amp;lt;export_orig_log_server&amp;gt;false&amp;lt;/export_orig_log_server&amp;gt;&lt;BR /&gt;&amp;lt;/data_enrichment&amp;gt;&lt;BR /&gt;&amp;lt;!-- Filter Configuration --&amp;gt;&lt;BR /&gt;&amp;lt;dynamicFilter&amp;gt;conf/FilterConfiguration.xml&amp;lt;/dynamicFilter&amp;gt;&lt;BR /&gt;&amp;lt;!-- Source section defines the properties of the input stream that will be exported --&amp;gt;&lt;BR /&gt;&amp;lt;source&amp;gt;&lt;BR /&gt;&amp;lt;log_files&amp;gt;1&amp;lt;/log_files&amp;gt;&amp;lt;!-- &amp;lt;Number&amp;gt; - read logs on-line | read logs from [number] days back (default 1) | specif&lt;BR /&gt;ic file name --&amp;gt;&lt;BR /&gt;&amp;lt;log_types&amp;gt;&amp;lt;/log_types&amp;gt;&amp;lt;!--all[default]|log|audit/--&amp;gt;&lt;BR /&gt;&amp;lt;folder&amp;gt;&amp;lt;/folder&amp;gt;&amp;lt;!--$FWDIR/log[default]|specific path--&amp;gt;&lt;BR /&gt;&amp;lt;read_mode&amp;gt;semi-unified&amp;lt;/read_mode&amp;gt;&amp;lt;!--raw|semi-unified[default]/--&amp;gt;&lt;BR /&gt;&amp;lt;/source&amp;gt;&lt;BR /&gt;&amp;lt;export_log_position&amp;gt;false&amp;lt;/export_log_position&amp;gt; &amp;lt;!-- True | False /--&amp;gt;&lt;BR /&gt;&amp;lt;export_log_link&amp;gt;false&amp;lt;/export_log_link&amp;gt; &amp;lt;!-- True | False /--&amp;gt;&lt;BR /&gt;&amp;lt;export_attachment_link&amp;gt;false&amp;lt;/export_attachment_link&amp;gt; &amp;lt;!-- True | False /--&amp;gt;&lt;BR /&gt;&amp;lt;export_link_ip&amp;gt;&amp;lt;/export_link_ip&amp;gt; &amp;lt;!-- empty [defaut] | external IP /--&amp;gt;&lt;BR /&gt;&amp;lt;export_attachment_ids&amp;gt;false&amp;lt;/export_attachment_ids&amp;gt; &amp;lt;!-- True | False /--&amp;gt;&lt;BR /&gt;&amp;lt;!-- Format section determines the form (headers and mappings) of the exported logs --&amp;gt;&lt;BR /&gt;&amp;lt;format type="syslog"&amp;gt; &amp;lt;!--syslog | cef | rsa | leef | generic | splunk | this parameter may differ from the type o&lt;BR /&gt;f destination, for example, destination type = files/format type = CEF --&amp;gt;&lt;BR /&gt;&amp;lt;resolver&amp;gt;&lt;BR /&gt;&amp;lt;mappingConfiguration&amp;gt;&amp;lt;/mappingConfiguration&amp;gt;&amp;lt;!--if empty the fields are sent as is without renaming--&amp;gt;&lt;BR /&gt;&amp;lt;exportAllFields&amp;gt;true&amp;lt;/exportAllFields&amp;gt; &amp;lt;!--in case exportAllFields=true - exported element in fieldsMapping.xml&lt;BR /&gt;is ignored and fields not from fieldsMapping.xml are exported as notMappedField field--&amp;gt;&lt;BR /&gt;&amp;lt;/resolver&amp;gt;&lt;BR /&gt;&amp;lt;!-- Format header configuration (actual to CEF see ./conf directory) --&amp;gt;&lt;BR /&gt;&amp;lt;formatHeaderFile&amp;gt;&amp;lt;/formatHeaderFile&amp;gt;&lt;BR /&gt;&amp;lt;/format&amp;gt;&lt;BR /&gt;&amp;lt;!-- Time In Milli Seconds --&amp;gt;&lt;BR /&gt;&amp;lt;time_in_milli&amp;gt;false&amp;lt;/time_in_milli&amp;gt;&lt;BR /&gt;&amp;lt;!-- Skip logs incase of failure in sending--&amp;gt;&lt;BR /&gt;&amp;lt;skip_failed_logs&amp;gt;false&amp;lt;/skip_failed_logs&amp;gt;&lt;BR /&gt;&amp;lt;!-- The following section is for future use of log filtering, please do not modify these values --&amp;gt;&lt;BR /&gt;&amp;lt;filter filter_out_by_connection="false"&amp;gt;&lt;BR /&gt;&amp;lt;field name="product"&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;VPN-1 &amp;amp;amp; FireWall-1&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;HTTPS Inspection&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;VPN-1&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;Security Gateway/Management&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;Firewall&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;FG&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/field&amp;gt;&lt;BR /&gt;&amp;lt;field name="fw_subproduct"&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;VPN-1 &amp;amp;amp; FireWall-1&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;HTTPS Inspection&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;VPN-1&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;Security Gateway/Management&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;Firewall&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;FG&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/field&amp;gt;&lt;BR /&gt;&amp;lt;/filter&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;lt;/export&amp;gt;&lt;/P&gt;
&lt;P&gt;[Expert@CP-MANAGEMENT:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 14:25:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262645#M59483</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T14:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262656#M59484</link>
      <description>&lt;P&gt;Is this the default result, or did you apply any filters to what should be sent? If not, can we modify this file without causing any errors in sending it to the SIEM?&lt;/P&gt;&lt;P&gt;I remember reading in LogExporter that it has some limitations for certain filters. I wanted to know if you applied any, and if so, did you follow any documentation?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 15:10:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262656#M59484</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-12T15:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262659#M59485</link>
      <description>&lt;P&gt;It is something my colleague configured in the lab, but it was not changed afterwards. This is what it looks like from smart console.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32084i616160C4A4A0D78F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32083iBF02BBFAC19C7766/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 15:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262659#M59485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T15:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262660#M59486</link>
      <description>&lt;P&gt;Interesting.&lt;/P&gt;&lt;P&gt;I didn't know it was possible to access the Smart-1 Cloud through the Smart Console. This is my first time experiencing this, and it has raised some questions.&lt;/P&gt;&lt;P&gt;If this is possible, I believe the logic for using LogExporter is the same for cloud management. But I confess that without documentation or a direct confirmation from Check Point, I'm hesitant to perform these configurations on a Smart-1.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 15:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262660#M59486</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-12T15:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262663#M59487</link>
      <description>&lt;P&gt;No worries my friend, I was new to S1C back in 2019, now I feel Im an expert lol. Here is the guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Overview.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Overview.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 15:34:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262663#M59487</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T15:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262672#M59488</link>
      <description>&lt;P&gt;Please refer to below, mate. Its pretty straight forward and easy to set up...well, as they say, everything in life is easy when you know it : - )&lt;/P&gt;
&lt;P&gt;Anyway, message me directly if you need help.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32085iE3BB383EBAC25C55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 17:48:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262672#M59488</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T17:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262676#M59489</link>
      <description>&lt;P&gt;Thank you very much for your help, the_rock. I've been working with Check Point for 4 years, but I'd never accessed a Smart-1 before.&lt;/P&gt;&lt;P&gt;Since you posted both sides of the issue, it raised another question for me.&lt;/P&gt;&lt;P&gt;If I configure something through the Smart-1 Cloud via the web using the forward to SIEM option and apply it, will that same configuration be visible through the Smart Console?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 18:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262676#M59489</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-12T18:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262677#M59490</link>
      <description>&lt;P&gt;Yea, 100%. Just remember, the ONLY thing you cant access when it comes to S1C is ssh, which is only available to TAC, but lets be honest, you literally never need that anyway. For what is worth, I always bring up same argument to people thinking about getting smart-1 cloud...say someone inadvertently makes a change on onprem mgmt they are not supposed to, well, if device is few hours away and no one on site, wont be fun day/night for anyone. With cloud, thats never a concern, as you can log in from any computer in the world with Internet access and revert any changes. Plus, CP maintains the software updates and backups are also always there, so it truly gives you piece of mind.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 18:28:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262677#M59490</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-12T18:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: [Smart-1 Cloud] - Log and Event Configuration for SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262678#M59491</link>
      <description>&lt;P&gt;So all the tests you were running weren't directly from an SSH connection to the Smart-1?&lt;/P&gt;&lt;P&gt;Because I was hoping I could access the expert mode of that Smart-1 and edit the file to perform the filtering of the columns that my SIEM team wants to receive.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 18:33:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-1-Cloud-Log-and-Event-Configuration-for-SIEM/m-p/262678#M59491</guid>
      <dc:creator>lucasfn</dc:creator>
      <dc:date>2025-11-12T18:33:30Z</dc:date>
    </item>
  </channel>
</rss>

