<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Exporter Checkpoint R80.40 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92651#M79162</link>
    <description>Alright so i configured a log exporter in Mgmt Server.. the syslog server is in the same vlan as that of MGMT Server. I can see the process running via commands - cp_log_export status cp_log_export server However, at the syslog server end no logs are visible it is just showing the Mgmt Firewall hostname and the process id.. am i missing something here ? Thanks</description>
    <pubDate>Tue, 28 Jul 2020 17:13:13 GMT</pubDate>
    <dc:creator>LostBoY</dc:creator>
    <dc:date>2020-07-28T17:13:13Z</dc:date>
    <item>
      <title>Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92620#M79157</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to integrate my Checkpoint instance to DataDog.. i am wondering what is the best way to do so.. should i just configure a syslog server , forward all Checkpoint logs to that syslog and integrate that syslog server with datadog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, i also came across "Log Exporter" feature in Checkpoint but i didnt get it completely. Does log exporter enables integration directly with SIEM tools ? do i need to install any additional plugins on the GWs for it to function.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 12:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92620#M79157</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2020-07-28T12:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92640#M79158</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;There are many approaches that you can do to achieve this. So far I've used a syslog server to export logs and then ship them to the right platform (e.g. Azure Log Analytics), and in some cases I have used OPSEC integration with some vendors and systems. In essence it boils down to your preference, needs and specifications.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Predrag&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 15:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92640#M79158</guid>
      <dc:creator>PredragPetrovic</dc:creator>
      <dc:date>2020-07-28T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92641#M79159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8988"&gt;@LostBoY&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I would suggest to use Log Exporter. It is really easy to configure and you can use filter as well.&lt;/P&gt;&lt;P&gt;If you use the Log Exporter, the remote SIEM tool will be recieve logs through syslog. You don't need to install any other plugins.&lt;/P&gt;&lt;P&gt;Please find&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_self"&gt;sk122323&amp;nbsp;&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 15:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92641#M79159</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2020-07-28T15:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92649#M79160</link>
      <description>Thanks for the reply.. so if i understand this correctly i need to use log exporter to send all the logs from Mgmt Server to a syslog server... i can then add that syslog server to the SIEM tool ?</description>
      <pubDate>Tue, 28 Jul 2020 16:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92649#M79160</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2020-07-28T16:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92650#M79161</link>
      <description>Thanks for the reply... so it means i should export the logs to a syslog server... then add that syslog server to the SIEM Also, there is an option to create a syslog server in SmartConsole via New Object -Server and so on.. is it one and the same thing.</description>
      <pubDate>Tue, 28 Jul 2020 17:00:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92650#M79161</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2020-07-28T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92651#M79162</link>
      <description>Alright so i configured a log exporter in Mgmt Server.. the syslog server is in the same vlan as that of MGMT Server. I can see the process running via commands - cp_log_export status cp_log_export server However, at the syslog server end no logs are visible it is just showing the Mgmt Firewall hostname and the process id.. am i missing something here ? Thanks</description>
      <pubDate>Tue, 28 Jul 2020 17:13:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92651#M79162</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2020-07-28T17:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92655#M79163</link>
      <description>&lt;P&gt;As I have said there are multiple ways to do this. What is the most logical way its up to you... When using cp_log_export tool after adding the log export just restart the added export and it will start exporting the logs. Ensure that necessary ports are open (e.g. Azure NSG's or AWS SecurityGroups where the Syslog is located).&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cp_log_export add name to_RemoteServer target-server X.X.X.X target-port 514 protocol udp format syslog&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cp_log_export restart name to_RemoteServer&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;After what you do from the syslog its up to you and DataDog agent &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 17:58:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92655#M79163</guid>
      <dc:creator>PredragPetrovic</dc:creator>
      <dc:date>2020-07-28T17:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92675#M79164</link>
      <description>&lt;P&gt;Thanks, i have configured log exporter like this.. however, at the syslog&amp;nbsp; server i can just see the process id and management server hostname displayed but no connection logs.. do i need to enable any thing else vis log exporter commands.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 05:33:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/92675#M79164</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2020-07-29T05:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/112158#M79165</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; did you ever solve this - I get exactly the same (R80.40) - my syslog server just receives Time/Log Server/PID - nothing useful!!&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Graham&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 17:59:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/112158#M79165</guid>
      <dc:creator>gdobson</dc:creator>
      <dc:date>2021-03-01T17:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/113944#M79166</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have updated my firewall to 80.40 and as i read the log_exporter is integrated. But via ssh i can't set the command cp_log_export because of invalid command .&lt;/P&gt;&lt;P&gt;Can someone help me please ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 13:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/113944#M79166</guid>
      <dc:creator>Sven</dc:creator>
      <dc:date>2021-03-18T13:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/116032#M79167</link>
      <description>&lt;P&gt;no unfortunately i didnt get any resolution for this.. i end up exporting logs from individual gateways but it doest not serve the purpose..i guess it does not include any audit logs or deny logs&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 16:13:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/116032#M79167</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-14T16:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125781#M79168</link>
      <description>&lt;P&gt;were you able to fix this ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 12:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125781#M79168</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-08-05T12:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125813#M79169</link>
      <description>&lt;P&gt;On R81 Log exporter basic settings can now be configured within the management object.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 21:21:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125813#M79169</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-08-05T21:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter Checkpoint R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125814#M79170</link>
      <description>&lt;P&gt;did you run cp_log_export from expert mode? This should work.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 21:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Checkpoint-R80-40/m-p/125814#M79170</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-08-05T21:22:37Z</dc:date>
    </item>
  </channel>
</rss>

