<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting a syslog facility code in cp_log_export? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92507#M79188</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I have tried to find a way to set a specific syslog Facility code for my auditlogs with the the cp_log_export function,&amp;nbsp; but I cannot find that feature. It seems to use the default Facility code 0 by default.&lt;BR /&gt;Does anyone know if this is possible or planned for any&amp;nbsp;&lt;SPAN&gt;coming releases?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mattias Jansson&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 08:34:07 GMT</pubDate>
    <dc:creator>Mattias_Jansson</dc:creator>
    <dc:date>2020-07-27T08:34:07Z</dc:date>
    <item>
      <title>Setting a syslog facility code in cp_log_export?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92507#M79188</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I have tried to find a way to set a specific syslog Facility code for my auditlogs with the the cp_log_export function,&amp;nbsp; but I cannot find that feature. It seems to use the default Facility code 0 by default.&lt;BR /&gt;Does anyone know if this is possible or planned for any&amp;nbsp;&lt;SPAN&gt;coming releases?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mattias Jansson&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92507#M79188</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2020-07-27T08:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a syslog facility code in cp_log_export?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92509#M79189</link>
      <description>&lt;P&gt;I think this was/is possible with&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115392&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk115392: How to export Check Point logs to a Syslog server using &lt;STRONG&gt;CPLogToSyslog :&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;(7-B) Syslog Indicators - Facility Indicators&lt;/H4&gt;
&lt;DIV&gt;
&lt;DIV id="Toggle_Syslog_Indicators_Facility_Indicators"&gt;
&lt;P&gt;The following table shows the values and meanings of Facility Indicators that are used in the &lt;STRONG&gt;&lt;CODE&gt;event_format&lt;/CODE&gt;&lt;/STRONG&gt; section of the policy file&lt;BR /&gt;(refer to section "&lt;SPAN class="checkpoint_navigate"&gt;(5-E) Configuration instructions - Rulebase&lt;/SPAN&gt;").&lt;/P&gt;
&lt;P&gt;The Facility Indicators are used to specify what type of program is logging the message.&lt;BR /&gt;This lets the administrator specify that messages from different facilities should be handled differently&lt;BR /&gt;(refer to &lt;A href="https://linux.die.net/man/5/syslog.conf" target="_blank" rel="noopener"&gt;https://linux.die.net/man/5/syslog.conf&lt;/A&gt;).&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92509#M79189</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-27T08:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a syslog facility code in cp_log_export?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92521#M79190</link>
      <description>&lt;P&gt;Interesting.&amp;nbsp;&lt;BR /&gt;That seems to be the older tool that was supported until R80.10.&amp;nbsp;&lt;BR /&gt;We are on R80.20.&amp;nbsp;&lt;BR /&gt;So I hope that the possibility to set the facility indicator will be implemented in coming relases of the new feature.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 12:33:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92521#M79190</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2020-07-27T12:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Setting a syslog facility code in cp_log_export?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92712#M79191</link>
      <description>&lt;P&gt;I have now found this:&amp;nbsp;&lt;A title="How to configure Security Gateway on Gaia OS to send FireWall logs to an external Syslog server
                
        
        
            Technical Level" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk87560&amp;amp;srcFavorites=favorites" target="_blank"&gt;sk87560: How to configure Security Gateway on Gaia OS to send FireWall logs to an external Syslog server Technical Level&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 08:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setting-a-syslog-facility-code-in-cp-log-export/m-p/92712#M79191</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-29T08:43:36Z</dc:date>
    </item>
  </channel>
</rss>

