<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending syslog from CheckPoint R81 to SIEM in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144287#M72618</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/66983"&gt;@Arturxr&lt;/a&gt;&amp;nbsp;please explain "&lt;SPAN&gt;administration data&lt;/SPAN&gt;", maybe with an example which information do you need to send to the SIEM.&lt;/P&gt;
&lt;P&gt;If you change something in the rulebase or change objects, these changes are collected in the audit log.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2022 11:58:36 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-03-21T11:58:36Z</dc:date>
    <item>
      <title>Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144268#M72615</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, tell me, is it possible to configure syslog so that administration data is also transmitted to SIEM (actions performed by administrators on the management server, events related to changing system objects?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 09:43:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144268#M72615</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-03-21T09:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144269#M72616</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/66983"&gt;@Arturxr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank" rel="noopener"&gt;Log Exporter - Check Point Log Export&lt;/A&gt;&amp;nbsp;will be the tool for your need. You can forward audit logs only .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 09:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144269#M72616</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-21T09:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144273#M72617</link>
      <description>&lt;P&gt;Yes, I studied this sk, only security and audit logs are sent, it turns out that they do not contain administration data and cannot be sent to siem in any way?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:25:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144273#M72617</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-03-21T10:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144287#M72618</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/66983"&gt;@Arturxr&lt;/a&gt;&amp;nbsp;please explain "&lt;SPAN&gt;administration data&lt;/SPAN&gt;", maybe with an example which information do you need to send to the SIEM.&lt;/P&gt;
&lt;P&gt;If you change something in the rulebase or change objects, these changes are collected in the audit log.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 11:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144287#M72618</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-21T11:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144294#M72619</link>
      <description>&lt;P&gt;In SIEM, it is necessary to transfer information on changing objects (rules, hosts, subnets, etc.)&lt;BR /&gt;This information comes through OPSEC, but can it be configured through the Log Exporter?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:14:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144294#M72619</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-03-21T13:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144296#M72620</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/66983"&gt;@Arturxr&lt;/a&gt;&amp;nbsp;as I wrote in my post, this information"&lt;SPAN&gt;changing objects (rules, hosts, subnets, etc."&lt;/SPAN&gt;&amp;nbsp;is logged in the audit logs of&amp;nbsp; your SMS and it's possible to send them to SIEM . Have a look at the audit log view in Smartconsole, every information shown there can be send to SIEM. There is no need for the use of the OPSEC interface, LogExporter does this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:28:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144296#M72620</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-21T13:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144298#M72621</link>
      <description>&lt;P&gt;I understand correctly? is it set up here?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Снимок.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15785i61F056498F767E20/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Снимок.PNG" alt="Снимок.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:28:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144298#M72621</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-03-21T13:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144299#M72622</link>
      <description>&lt;P&gt;Yes, that's correct. If you want to send audit logs only you have to do advanced configuration and change the configuration xml file. Change&amp;nbsp;&lt;SPAN&gt;&amp;lt;log_types&amp;gt; all &amp;lt;/log_types&amp;gt; to&amp;nbsp;&amp;nbsp;&amp;lt;log_types&amp;gt; audit &amp;lt;/log_types&amp;gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:41:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144299#M72622</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-21T13:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144301#M72623</link>
      <description>&lt;P&gt;Thanks, where can I find this xml file?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144301#M72623</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-03-21T13:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144302#M72624</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Everything you need is found here, please read this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank" rel="noopener noreferrer"&gt;Log Exporter - Check Point Log Export&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Log Exporter configuration for the target server is saved in:&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;$EXPORTERDIR/targets/&amp;lt;Name of Log Exporter Configuration&amp;gt;/targetConfiguration.xml&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 14:21:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/144302#M72624</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-21T14:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232687#M72625</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;For a company using Splunk as their SIEM solution, does selecting the format "Splunk" in the "Data Manipulation" page of the Log Exporter provide any major benefits over selecting "Syslog"?&lt;/P&gt;&lt;P&gt;What could be the advantages and disadvantages of selecting the format "Splunk"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 08:22:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232687#M72625</guid>
      <dc:creator>jimmyjose2980</dc:creator>
      <dc:date>2024-11-14T08:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232793#M72626</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45403"&gt;@jimmyjose2980&lt;/a&gt;&amp;nbsp; if you export your data directly to Splunk you have to choose Splunk, if you export to a syslog server you choose syslog. With the correct data manipulation you get the correct mapping from Check Point fields to Splunk fields &amp;nbsp;in the data format. You can configure your own mapping for every data fields, but Check Point did this job and default profiles for the most common SIEM solutions are ready to use.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 20:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232793#M72626</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-11-14T20:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232820#M72627</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;, thank you for your response!&lt;/P&gt;&lt;P&gt;From what I understand from the documentation is that regardless of whether I choose "Syslog" or "Splunk" as the log format in Log Exporter, I can either select TCP or UDP protocol. Is there a way I could configure HTTPS to encrypt the packets from Check Point to Syslog or Splunk?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232820#M72627</guid>
      <dc:creator>jimmyjose2980</dc:creator>
      <dc:date>2024-11-14T22:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232861#M72628</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45403"&gt;@jimmyjose2980&lt;/a&gt;&amp;nbsp;see&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_LoggingAndMonitoring_AdminGuide/Content/Topics-LMG/Log-Exporter-TLS-configuration.htm?tocpath=Log%20Exporter%7C_____4" target="_blank" rel="noopener"&gt;Log Exporter TLS Configuration&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_LoggingAndMonitoring_AdminGuide/Content/Topics-LMG/Log-Exporter-SIEM-specific-instructions.htm" target="_blank"&gt;Log Exporter Instructions for Specific SIEM&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 07:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232861#M72628</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-11-15T07:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232873#M72629</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;, thanks! This will help me set up TLS configuration if I use the "Syslog" log format in "Data Manipulation". However, this configuration does not seem to support TLS configuration if I chose "Splunk" as the log format. What is your take on it?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 09:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232873#M72629</guid>
      <dc:creator>jimmyjose2980</dc:creator>
      <dc:date>2024-11-15T09:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232876#M72630</link>
      <description>&lt;P&gt;The connection to splunk can be encrypted. Follow&amp;nbsp;&lt;A title="Log Exporter Instructions for Specific SIEM" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_LoggingAndMonitoring_AdminGuide/Content/Topics-LMG/Log-Exporter-SIEM-specific-instructions.htm" target="_blank" rel="noopener"&gt;Log Exporter Instructions for Specific SIEM&lt;/A&gt;&amp;nbsp; and a more detailed description&amp;nbsp;&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/Utilizing-Mutual-TLS-Authentication-with-Log-Exporter/m-p/179138#M34664" target="_blank"&gt;Utilizing Mutual TLS Authentication with Log Expor... - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 12:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/232876#M72630</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-11-15T12:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/233227#M72631</link>
      <description>&lt;P&gt;Great, thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 11:14:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/233227#M72631</guid>
      <dc:creator>jimmyjose2980</dc:creator>
      <dc:date>2024-11-20T11:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/256259#M72632</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Is it possible to integrate a Check Point MDS against a Wazuh SIEM?&lt;/P&gt;
&lt;P&gt;The configuration to send the logs to the SIEM (if Wazuh is supported) must be done in the main MDS or is it done in all the CMA (1x1)?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 14:18:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/256259#M72632</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-08-31T14:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from CheckPoint R81 to SIEM</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/256290#M72633</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;you can do an export from only some CMAs or for all, it depends on your needs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But you can do it for all, see the documentation&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Log_Exporter/EN/Content/Topics/Deployment-CLI.htm?Highlight=mds" target="_blank"&gt;Deployment of Log Exporter in CLI&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The "&lt;CODE&gt;domain-server&lt;/CODE&gt;" argument is mandatory on a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mdsecmgmt variable"&gt;Multi-Domain Security Management&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Server /&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mdls variable"&gt;Multi-Domain Log Server&lt;/SPAN&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;mds&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(in small letters) - Exports logs from only the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;MDS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;level.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;CODE&gt;all&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(in small letters) - Exports logs from all&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_domains variable"&gt;Domains&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I'm not familiar with export to Wazuh but it should work. You have to play something with the fields of the export.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 08:11:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sending-syslog-from-CheckPoint-R81-to-SIEM/m-p/256290#M72633</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-09-01T08:11:00Z</dc:date>
    </item>
  </channel>
</rss>

