<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point MDS / Gateway Logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99786#M78059</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Yes &lt;/STRONG&gt;to most questions &amp;amp; please read the log-Exporter sk (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_self" rel="noopener noreferrer"&gt;sk122323&lt;/A&gt;), as Val suggested.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;to answer your last question:&lt;BR /&gt;&lt;SPAN&gt;"Can you configure multiple syslog servers in active / passive mode. That you don't have duplicated logs but the logs get sent when one syslog server fails?"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not exactly, an HA/Backup like system for log-exporting (cp_log_export) is not currently available. You can simply send simultaneously to 2 different syslog servers = duplication.&lt;BR /&gt;BUT assuming you have 2 different log-servers when one is a backup Log-Server for 1 GW (you can configure that), then you can configure both to export to same syslog server.&lt;BR /&gt;and only once the backup LS starts actually logging (once Primary Log-Server is down for any reason), it'll actually export these logs.&lt;BR /&gt;that is a sort-of backup active/passive log-exporter, but it depends on the base Log-Server receiving the logs.&lt;BR /&gt;&lt;BR /&gt;Hope that helped.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Oct 2020 07:04:06 GMT</pubDate>
    <dc:creator>Dror_Aharony</dc:creator>
    <dc:date>2020-10-22T07:04:06Z</dc:date>
    <item>
      <title>Check Point MDS / Gateway Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99783#M78057</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I'm trying to onboard Check Point logs at the moment and could need some help.&lt;/P&gt;&lt;P&gt;The goal is to send all Logs to a Syslog server and then bring them into a log pipeline.&lt;/P&gt;&lt;P&gt;As I understand Check Point has two log sources: traffic and security logs are exported from the MDS log server with "cp_log_export" and the audit logs and device logs from the gateways are configured with the clish syslog commands. Is that correct?&lt;/P&gt;&lt;P&gt;Now I face these problems:&lt;/P&gt;&lt;P&gt;Is there a way to send gateway (GAIA) logs via TCP or even syslog over TLS?&lt;/P&gt;&lt;P&gt;Can you export the "cp_log_export" via syslog but still use the Splunk app?&lt;/P&gt;&lt;P&gt;Can you configure multiple syslog servers in active / passive mode. That you don't have duplicated logs but the logs get sent when one syslog server fails?&lt;/P&gt;&lt;P&gt;Thanks a lot for the help.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 06:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99783#M78057</guid>
      <dc:creator>Logger</dc:creator>
      <dc:date>2020-10-22T06:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point MDS / Gateway Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99785#M78058</link>
      <description>&lt;P&gt;Please read&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_self"&gt;sk122323&lt;/A&gt;, you should have all the answers there&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 06:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99785#M78058</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-22T06:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point MDS / Gateway Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99786#M78059</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Yes &lt;/STRONG&gt;to most questions &amp;amp; please read the log-Exporter sk (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_self" rel="noopener noreferrer"&gt;sk122323&lt;/A&gt;), as Val suggested.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;to answer your last question:&lt;BR /&gt;&lt;SPAN&gt;"Can you configure multiple syslog servers in active / passive mode. That you don't have duplicated logs but the logs get sent when one syslog server fails?"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not exactly, an HA/Backup like system for log-exporting (cp_log_export) is not currently available. You can simply send simultaneously to 2 different syslog servers = duplication.&lt;BR /&gt;BUT assuming you have 2 different log-servers when one is a backup Log-Server for 1 GW (you can configure that), then you can configure both to export to same syslog server.&lt;BR /&gt;and only once the backup LS starts actually logging (once Primary Log-Server is down for any reason), it'll actually export these logs.&lt;BR /&gt;that is a sort-of backup active/passive log-exporter, but it depends on the base Log-Server receiving the logs.&lt;BR /&gt;&lt;BR /&gt;Hope that helped.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 07:04:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-MDS-Gateway-Logs/m-p/99786#M78059</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-10-22T07:04:06Z</dc:date>
    </item>
  </channel>
</rss>

