<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic log Exporter error in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120375#M75603</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;Single CMA R80.40 T29 getting error below both on production and lab environments. Anyone come across this issue? Upgrading to a higher take is not an option as upgrading to T102 (log exporter worked here) but caused severe issues on the prod environment after policy was pushed (have case open but no proper RC yet). Had to roll back. Speculate trying another higher HF? = very unlikely!!! . Maybe move away from CP? = looks like an option.&lt;/P&gt;&lt;DIV&gt;[Expert@SMS# cp_log_export add name logexport1 target-server x.x.x.x target-port 514 protocol tcp format splunk read-mode semi-unified export-attachment-ids true&lt;BR /&gt;&lt;STRONG&gt;Error: Argument [export-attachment-ids] is undefined for command: [add]&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Same command run on Lab R80.10 works. Go figure.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Cheers!&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;supruzer&lt;/DIV&gt;</description>
    <pubDate>Fri, 04 Jun 2021 14:42:58 GMT</pubDate>
    <dc:creator>supruzer1</dc:creator>
    <dc:date>2021-06-04T14:42:58Z</dc:date>
    <item>
      <title>log Exporter error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120375#M75603</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;Single CMA R80.40 T29 getting error below both on production and lab environments. Anyone come across this issue? Upgrading to a higher take is not an option as upgrading to T102 (log exporter worked here) but caused severe issues on the prod environment after policy was pushed (have case open but no proper RC yet). Had to roll back. Speculate trying another higher HF? = very unlikely!!! . Maybe move away from CP? = looks like an option.&lt;/P&gt;&lt;DIV&gt;[Expert@SMS# cp_log_export add name logexport1 target-server x.x.x.x target-port 514 protocol tcp format splunk read-mode semi-unified export-attachment-ids true&lt;BR /&gt;&lt;STRONG&gt;Error: Argument [export-attachment-ids] is undefined for command: [add]&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Same command run on Lab R80.10 works. Go figure.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Cheers!&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;supruzer&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Jun 2021 14:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120375#M75603</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-06-04T14:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: log Exporter error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120454#M75604</link>
      <description>&lt;P&gt;What "severe issues" were caused by upgrading?&lt;BR /&gt;Maybe send me the SR in a PM.&lt;BR /&gt;In any case, this looks like a bug in the version you're running that has been fixed in a later JHF, according to what you're saying.&lt;BR /&gt;The only other option would be to ask TAC to backport the relevant fix to the release you're on (not sure what fix that would be).&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 02:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120454#M75604</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-07T02:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: log Exporter error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120519#M75605</link>
      <description>&lt;P&gt;PhoneBoy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the prompt response. I will send you the TAC case separately for the prod issue. Will ask TAC if we can get a log exporter running without going through an upgrade-don't have a case for this-since I wanted to find out if our general public know about this error and tried something that worked.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We also have a SmartEvent server at 80.40 T29 which also serves as a log server for the same environment. Can log exporter work on a SmartEvent/Reporter? We would be able to upgrade it since no policy pushes required.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 15:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120519#M75605</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-06-07T15:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: log Exporter error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120524#M75606</link>
      <description>&lt;P&gt;Log Exporter runs on a log server, and yes can be run on the same system as SmartEvent.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 15:27:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/120524#M75606</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-07T15:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: log Exporter error</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/123744#M75607</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;&lt;P&gt;Just wanted to let you know that I was able to export logs from Eventia server to Splunk. Once the Eventia server was upgraded to R80.40 T119 Log exporter was able to run successfully.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Big thank you my friend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 21:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/log-Exporter-error/m-p/123744#M75607</guid>
      <dc:creator>supruzer1</dc:creator>
      <dc:date>2021-07-13T21:54:03Z</dc:date>
    </item>
  </channel>
</rss>

