<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Exporter - additional fields in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133312#M74061</link>
    <description>&lt;P&gt;thanks PhoneBoy - indeed accounting does enable the packet/bytes in/out and are visible in syslog. What about other "fields" - how can I customize the log output ?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2021 14:36:18 GMT</pubDate>
    <dc:creator>H4ppyM3</dc:creator>
    <dc:date>2021-11-05T14:36:18Z</dc:date>
    <item>
      <title>Log Exporter - additional fields</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133242#M74059</link>
      <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help me with configuration of some extra fields to be exported to our syslog&amp;nbsp; via cp_log_exporter ? &amp;nbsp;I’ve a requirement that also&amp;nbsp; in the log received by syslog to see “bytes in/out “&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking the sk122323&lt;/P&gt;&lt;P&gt;Steps:&lt;/P&gt;&lt;P&gt;a) On my MDS under the specific domain I location I modify following file: targetConfiguration.xml&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;lt;mappingConfiguration&amp;gt;&amp;nbsp; fieldsMapping.xml&amp;nbsp; &amp;lt;/mappingConfiguration&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;lt;exportAllFields&amp;gt; false&amp;lt;/exportAllField&lt;BR /&gt;&lt;BR /&gt;b)&amp;nbsp; In file: fieldsMapping.xml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;STRONG&gt;exported&amp;gt;true&amp;lt;/exported&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;required&amp;gt;true&amp;lt;/required&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;origName&amp;gt;src&amp;lt;/origName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dstName&amp;gt;cef_src&amp;lt;/dstName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;field&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;exported&amp;gt;true&amp;lt;/exported&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;required&amp;gt;true&amp;lt;/required&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;origName&amp;gt;dst&amp;lt;/origName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dstName&amp;gt;cef_dst&amp;lt;/dstName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;field&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;exported&amp;gt;true&amp;lt;/exported&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;required&amp;gt;true&amp;lt;/required&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;origName&amp;gt;sent_bytes&amp;lt;/origName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dstName&amp;gt;sent_bytes&amp;lt;/dstName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;exported&amp;gt;true&amp;lt;/exported&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;required&amp;gt;true&amp;lt;/required&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;origName&amp;gt;received_bytes&amp;lt;/origName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dstName&amp;gt;received_bytes&amp;lt;/dstName&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/field&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;table&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still – it does not work.&lt;BR /&gt;Log fields mapping can be found here :&amp;nbsp; sk144192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Restart cp_log_export.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 04 Nov 2021 17:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133242#M74059</guid>
      <dc:creator>H4ppyM3</dc:creator>
      <dc:date>2021-11-04T17:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - additional fields</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133281#M74060</link>
      <description>&lt;P&gt;My understanding is this a new log entry is sent every 10 minutes or so with the bytes in/out, assuming either accounting is enabled or the rule used App Control with Detailed or Extended logs.&amp;nbsp;&lt;BR /&gt;The initial log entry certainly won’t have it…by design.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 04:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133281#M74060</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-05T04:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - additional fields</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133312#M74061</link>
      <description>&lt;P&gt;thanks PhoneBoy - indeed accounting does enable the packet/bytes in/out and are visible in syslog. What about other "fields" - how can I customize the log output ?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 14:36:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133312#M74061</guid>
      <dc:creator>H4ppyM3</dc:creator>
      <dc:date>2021-11-05T14:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - additional fields</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133319#M74062</link>
      <description>&lt;P&gt;As far as I know, it should export more or less everything by default.&lt;BR /&gt;What precise fields are missing from the output?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 16:04:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-additional-fields/m-p/133319#M74062</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-05T16:04:46Z</dc:date>
    </item>
  </channel>
</rss>

