<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log - Accounting in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107250#M77181</link>
    <description>&lt;P&gt;Good afternoon everyone!&lt;/P&gt;&lt;P&gt;We are trying to implement external log with accounting updates. We have a simple rule setup that matches telnet traffic, and it is exporting to our syslog (using cp_log_exporter to a splunk server), however it is only sending the log when a connection opens and when the user disconnects the telnet session. It is my understanding from the documentation that with accounting enabled, I should see a log every 10 minutes for this connection, is that not right? Am I perhaps missing another configuration necessary for this?&lt;/P&gt;&lt;P&gt;Oh, I forgot to mention, we are running R81 VM in a test environment with VSX.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SH_ 2021-01-07 637.jpg" style="width: 891px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10100i9811082B2A796590/image-dimensions/891x50?v=v2" width="891" height="50" role="button" title="SH_ 2021-01-07 637.jpg" alt="SH_ 2021-01-07 637.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;[Expert@CheckPoint-Mgmt:0]# cp_log_export show&lt;/P&gt;&lt;P&gt;name: syslog2&lt;BR /&gt;enabled: true&lt;BR /&gt;target-server: 172.20.10.152&lt;BR /&gt;target-port: 514&lt;BR /&gt;protocol: udp&lt;BR /&gt;format: splunk&lt;BR /&gt;read-mode: semi-unified&lt;BR /&gt;export-attachment-ids: false&lt;BR /&gt;export-link: false&lt;BR /&gt;export-attachment-link: false&lt;BR /&gt;time-in-milli: false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2021 23:51:28 GMT</pubDate>
    <dc:creator>RKinsp</dc:creator>
    <dc:date>2021-01-07T23:51:28Z</dc:date>
    <item>
      <title>Log - Accounting</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107250#M77181</link>
      <description>&lt;P&gt;Good afternoon everyone!&lt;/P&gt;&lt;P&gt;We are trying to implement external log with accounting updates. We have a simple rule setup that matches telnet traffic, and it is exporting to our syslog (using cp_log_exporter to a splunk server), however it is only sending the log when a connection opens and when the user disconnects the telnet session. It is my understanding from the documentation that with accounting enabled, I should see a log every 10 minutes for this connection, is that not right? Am I perhaps missing another configuration necessary for this?&lt;/P&gt;&lt;P&gt;Oh, I forgot to mention, we are running R81 VM in a test environment with VSX.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SH_ 2021-01-07 637.jpg" style="width: 891px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10100i9811082B2A796590/image-dimensions/891x50?v=v2" width="891" height="50" role="button" title="SH_ 2021-01-07 637.jpg" alt="SH_ 2021-01-07 637.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;[Expert@CheckPoint-Mgmt:0]# cp_log_export show&lt;/P&gt;&lt;P&gt;name: syslog2&lt;BR /&gt;enabled: true&lt;BR /&gt;target-server: 172.20.10.152&lt;BR /&gt;target-port: 514&lt;BR /&gt;protocol: udp&lt;BR /&gt;format: splunk&lt;BR /&gt;read-mode: semi-unified&lt;BR /&gt;export-attachment-ids: false&lt;BR /&gt;export-link: false&lt;BR /&gt;export-attachment-link: false&lt;BR /&gt;time-in-milli: false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 23:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107250#M77181</guid>
      <dc:creator>RKinsp</dc:creator>
      <dc:date>2021-01-07T23:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Log - Accounting</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107334#M77182</link>
      <description>&lt;P&gt;That’s how often we send updates to the log server (every 10 minutes), but it may not translate to a log that is exported via Log Exporter until the connection is closed.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 00:44:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107334#M77182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-09T00:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Log - Accounting</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107470#M77183</link>
      <description>&lt;P&gt;Hi PhoneBoy, thanks for your response!&lt;/P&gt;&lt;P&gt;Testing these past few days, I figured out that by changing the "Update Account Log every" to 600 seconds, the system sends and updated log every 10 minutes to my log server. I changed this setting for both the FW and the Management Server, so I'm not sure which one made the difference (or if you need both) but I will keep testing.&lt;/P&gt;&lt;P&gt;One issue I have now is that I am unable to identify middle and end logs. From my tests, the LogID field is 0 for the first log of the connection and 6 for the middle and end. There are other fields that I am unsure what they mean (_pos, &lt;SPAN class="t"&gt;nsons), but I will probably start another post on this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;RK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SH_ 2021-01-11 2225.jpg" style="width: 643px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10156i3736536D066AF0AE/image-dimensions/643x341?v=v2" width="643" height="341" role="button" title="SH_ 2021-01-11 2225.jpg" alt="SH_ 2021-01-11 2225.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 12:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Log-Accounting/m-p/107470#M77183</guid>
      <dc:creator>RKinsp</dc:creator>
      <dc:date>2021-01-11T12:15:08Z</dc:date>
    </item>
  </channel>
</rss>

