<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PBR configuration is missing on Audit log in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101274#M7932</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;One of the customer environment is running on R80.30. The Audit team found that PBR-related changes are missing in audit logs, but we can see routing changes in the audit log. If it is not possible please share audit log details related to the gateway.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 07:44:17 GMT</pubDate>
    <dc:creator>User-checkpoint</dc:creator>
    <dc:date>2020-11-06T07:44:17Z</dc:date>
    <item>
      <title>PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101274#M7932</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;One of the customer environment is running on R80.30. The Audit team found that PBR-related changes are missing in audit logs, but we can see routing changes in the audit log. If it is not possible please share audit log details related to the gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 07:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101274#M7932</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T07:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101310#M7933</link>
      <description>&lt;P&gt;I put the question on you: what precisely are you seeing versus what you expect to see?&lt;BR /&gt;If you prefer not to share these details in public, I recommend a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 15:32:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101310#M7933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-06T15:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101326#M7934</link>
      <description>&lt;P&gt;We are expecting if someone performs PBR-related changes should be captured in the audit log, the routing changes are captured but PBR changes are missing so if I'm not mistaken PBR related configuration changes should be captured?&lt;/P&gt;&lt;P&gt;Herewith I have shared my lab output..&lt;/P&gt;&lt;P&gt;I&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8799iE7B55360B6AC2C7C/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMG.PNG" alt="IMG.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 16:39:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101326#M7934</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T16:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101327#M7935</link>
      <description>&lt;P&gt;The audit logs in SmartConsole will only show changes made via SmartConsole or the API.&amp;nbsp;&lt;BR /&gt;For OS-level changes like routing, the better place to look is /var/log/messages.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 16:56:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101327#M7935</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-06T16:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101328#M7936</link>
      <description>&lt;P&gt;This is distributed architecture. The customer wants to feed routing changes, PBR related changes to the SIEM solution. So please recommend the best way to achieve this requirement. We already using log exporter to export security and audit logs to SIEM solution. But the customer is now concern about routing and PBR related changes should be captured by SIEM.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 17:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101328#M7936</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T17:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101330#M7937</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36401"&gt;@User-checkpoint&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Changing PBR is a configuration change done on the gateways.&lt;/P&gt;
&lt;P&gt;To get this in your SIEM solution you have to export audit logs from your gateway to your SIEM or you can send these logs to your management.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="screen.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8800i84FFCCB90A27453D/image-size/large?v=v2&amp;amp;px=999" role="button" title="screen.png" alt="screen.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 17:34:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101330#M7937</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-11-06T17:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101331#M7938</link>
      <description>&lt;P&gt;You can configure the Gaia OS to directly send its syslog message elsewhere (e.g. your SIEM solution).&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 17:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101331#M7938</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-06T17:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101333#M7939</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;mentioned configuration already in place. but behaviour is same&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 18:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101333#M7939</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T18:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101334#M7940</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; if I integrate gateway to SIEM via syslog messages, the concern is SIEM already integrated with SMS, will security logs be duplicated in SIEM solution?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 18:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101334#M7940</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T18:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101335#M7941</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36401"&gt;@User-checkpoint&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you set a remote system logging server? This should be your SIEM or a syslog server which is forwarding these audit logs to SIEM.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 19:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101335#M7941</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-11-06T19:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101336#M7942</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;This is distributed architecture, the gateway is forwarding to SMS, and SMS will forward to SIEM solution via cp log exporter, where we cannot see PBR changes even in SMS. So I need to know how to pass PBR related changelogs to the SIEM solution&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 19:09:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101336#M7942</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T19:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101337#M7943</link>
      <description>&lt;P&gt;Gaia OS logs and Security Logs are entirely separate things&amp;nbsp;unless you've checked the "Send syslog messages to management server" option as shown above, which is not the default.&lt;BR /&gt;Even so, if Gaia OS logs are sent to management, they may not be parsed in the most useful way, particularly if they are then sent to your SIEM.&amp;nbsp;&lt;BR /&gt;Highly recommend exporting those logs to your SIEM separately.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 19:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101337#M7943</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-06T19:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101338#M7944</link>
      <description>&lt;P&gt;So this is very new to me and my team, below are the concerns, if we use a remote system logging mechanism to pass to the SIEM solution&lt;/P&gt;&lt;P&gt;1. which Syslog level needs to be configured to get configuration changes, login failure&lt;/P&gt;&lt;P&gt;2. Do we have any SK regarding Syslog field information since manual field indexing is required which manual procedure&lt;/P&gt;&lt;P&gt;I believe this is a common audit/SIEM integration use case when it comes to BFSI segmentation (If I'm not mistaken, PCIDSS required to capture configuration changes in SIEM)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 19:19:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101338#M7944</guid>
      <dc:creator>User-checkpoint</dc:creator>
      <dc:date>2020-11-06T19:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: PBR configuration is missing on Audit log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101462#M7945</link>
      <description>&lt;P&gt;I would review the messages you are interested in to determine the correct logging level as I do not know them offhand.&lt;BR /&gt;The only document I'm aware of that describes Gaia Syslog messages is:&amp;nbsp;&lt;A href="https://downloads.checkpoint.com/dc/download.htm?ID=24459" target="_blank"&gt;https://downloads.checkpoint.com/dc/download.htm?ID=24459&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 05:19:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-configuration-is-missing-on-Audit-log/m-p/101462#M7945</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-09T05:19:51Z</dc:date>
    </item>
  </channel>
</rss>

