<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Exporter exporting to splunk in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168706#M69717</link>
    <description>&lt;P&gt;I see. There is another team in charge of splunk so I can't really do that but I'll check with them, if I can't I think I'll have to use a splunk agent on another machine to specify the index,&lt;/P&gt;&lt;P&gt;Do you know how can I send only a certain type of logs? for example audit logs.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 09:00:09 GMT</pubDate>
    <dc:creator>bob111</dc:creator>
    <dc:date>2023-01-23T09:00:09Z</dc:date>
    <item>
      <title>Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168666#M69711</link>
      <description>&lt;P&gt;Hello, I want to export audit logs from my firewall to a splunk server. do I need to create a vm with a splunk agent that will forward the logs? Or the log exporter does not need that?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 13:27:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168666#M69711</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-22T13:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168670#M69712</link>
      <description>&lt;P&gt;I dont believe you need that. Check out below post, see if it helps you. My colleague and I did this for the customer couple of years back.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Log-exporter-amp-Splunk-TLS/m-p/126164#M27609" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Log-exporter-amp-Splunk-TLS/m-p/126164#M27609&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2023 15:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168670#M69712</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-22T15:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168694#M69713</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;thanks for the reply! I think I phrased my my question wrong, I meant can I specify in my log exporter to which index in the splunk server to send the logs to?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 07:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168694#M69713</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-23T07:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168700#M69714</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Syntax:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;cp_log_export add name &amp;lt;&lt;EM&gt;Name&lt;/EM&gt;&amp;gt; [domain-server {mds | all}] target-server &amp;lt;&lt;EM&gt;HostName or IP address of Target Server&lt;/EM&gt;&amp;gt; target-port &amp;lt;&lt;EM&gt;Port on Target Server&lt;/EM&gt;&amp;gt; protocol {udp | tcp} format {syslog | splunk |&amp;nbsp;cef | leef | generic | json | logrhythm | rsa} [&amp;lt;&lt;EM&gt;Optional Arguments&lt;/EM&gt;&amp;gt;]&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;Refer also: sk12232&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168700#M69714</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-23T08:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168702#M69715</link>
      <description>&lt;P&gt;Hey, thanks for the reply! is there an argument used to specify the index in the splunk server?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168702#M69715</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-23T08:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168704#M69716</link>
      <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;normally you define such things at the destination system - ie splunk - at input config.&lt;BR /&gt;I have configured a dedicated UDP port, where CP Management is logging to and set at splunk site that logs received through this and from that host into the dedicated index.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 08:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168704#M69716</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-01-23T08:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168706#M69717</link>
      <description>&lt;P&gt;I see. There is another team in charge of splunk so I can't really do that but I'll check with them, if I can't I think I'll have to use a splunk agent on another machine to specify the index,&lt;/P&gt;&lt;P&gt;Do you know how can I send only a certain type of logs? for example audit logs.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 09:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168706#M69717</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-23T09:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168707#M69718</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323#Filter%20Configuration" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323#Filter%20Configuration&lt;/A&gt;&lt;/P&gt;
&lt;TABLE class="footnote" border="1" width="100%" cellspacing="4" cellpadding="5"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;CODE&gt;&amp;lt;log_types&amp;gt;&amp;lt;/log_types&amp;gt;&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;Determines which logs to export based on their type&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding indexer. In our env, this was done on splunk side. Depends on your Splunk (audit log/access log/visibility for several teams)&lt;/P&gt;
&lt;P&gt;Optional, you might run serveral log exporter instances sending to different IP/ports&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 09:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168707#M69718</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2023-01-23T09:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168739#M69719</link>
      <description>&lt;P&gt;Let me know if you cant get syntax right, I have what my colleague and I did for this customer we worked with. Sadly, I dont know what has to be done on other side (I think we dealt with Qradar), but either way, 3rd party support should be able to get that side of things working.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 13:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168739#M69719</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-23T13:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168919#M69720</link>
      <description>&lt;P&gt;Hey, my log exporter is working but I see the logs on my splunk server in a json format even though the log exporter is sending the logs in a syslog format. Do you know why is that? Or maybe do you have an example of how the logs from should look like in the splunk server?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168919#M69720</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-24T12:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168925#M69721</link>
      <description>&lt;P&gt;Do you have the exact syntax on CP side?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:47:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168925#M69721</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T12:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168927#M69722</link>
      <description>&lt;P&gt;What do you mean?&lt;/P&gt;&lt;P&gt;When I look at the logs from the log exporter that I receive on a vm that is the splunk agent I see information that I don't see when I look in the index in the splunk server&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:56:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168927#M69722</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-24T12:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168931#M69723</link>
      <description>&lt;P&gt;You can run cp_log_export show from expert mode on mgmt and see what you get. Thats output I was asking for, if you can send it...please blur out any SENSITIVE info.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:54:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168931#M69723</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T12:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168932#M69724</link>
      <description>&lt;P&gt;Bob, if possible, can you show us how you configured the log export (i.e. CLI command with relevant portions like log format)&lt;BR /&gt;at least in 81.20 there is an own splunk log format&lt;/P&gt;&lt;P&gt;cp_log_export show&lt;/P&gt;&lt;P&gt;should show you the settings actually set&lt;/P&gt;&lt;P&gt;And you should check with your Splunk Colleague, how the data import has been configured.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168932#M69724</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-01-24T12:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168933#M69725</link>
      <description>&lt;P&gt;name: Log_Exporter&lt;BR /&gt;enabled: true&lt;BR /&gt;target-server: 192.168.10.15&lt;BR /&gt;target-port: 514&lt;BR /&gt;protocol: udp&lt;BR /&gt;format: syslog&lt;BR /&gt;read-mode: semi-unified&lt;BR /&gt;export-attachment-ids: false&lt;BR /&gt;export-link: false&lt;BR /&gt;export-attachment-link: false&lt;BR /&gt;time-in-milli: false&lt;BR /&gt;export-log-position: false&lt;BR /&gt;reconnect-interval: Not Configured, using default&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 13:03:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168933#M69725</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-24T13:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168947#M69726</link>
      <description>&lt;P&gt;That looks right to me. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1663"&gt;@Nüüül&lt;/a&gt;&amp;nbsp;said, maybe double check with soemone on the other side what they are seeing.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 14:02:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/168947#M69726</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T14:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169136#M69727</link>
      <description>&lt;P&gt;Thank you for all the help. Do you know where are the logs from the log exporter saved in the vm (target server)? I mean what is the path?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169136#M69727</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-25T15:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169144#M69728</link>
      <description>&lt;P&gt;Are you referring to CP or Splunk side?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169144#M69728</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-25T15:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169145#M69729</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;cannot be said in general. it depends on the config of the target server. According Splunk Documentation:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Data/Configureyourinputs" target="_blank"&gt;Other ways to get data in - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For example, if you have installed an app like Check Points TA app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169145#M69729</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-01-25T15:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter exporting to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169255#M69730</link>
      <description>&lt;P&gt;I'm referring to the side receiving the logs, for me it is a vm that has a splunk agent installed on it that forwards the logs to the splunk server. when I use tcpdump on the vm to see the logs I receive from the log exporter I can see information, but when I look in the splunk server I see the logs in a json format and I don't see the information I saw when I used tcpdump on the vm.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 09:31:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-exporting-to-splunk/m-p/169255#M69730</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2023-01-26T09:31:02Z</dc:date>
    </item>
  </channel>
</rss>

