<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LEA vs Log exporter to send to splunk in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84165#M80366</link>
    <description>&lt;P&gt;&lt;STRONG&gt;cpinfo -y all&lt;/STRONG&gt; (for JHF version) too, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 08:03:19 GMT</pubDate>
    <dc:creator>Dror_Aharony</dc:creator>
    <dc:date>2020-05-05T08:03:19Z</dc:date>
    <item>
      <title>LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84093#M80360</link>
      <description>&lt;P&gt;We are in the process of configuring our CP environment to send logs to a managed Splunk instance.&amp;nbsp; With that said we are trying to get a definitive answer on the direction to go (LEA / Log Exporter)&amp;nbsp; Our partner wants to use LEA but it seems like that is old school and will limit us moving forward.&amp;nbsp; So the questions are:&lt;/P&gt;&lt;P&gt;What is the road map for LEA support?&lt;/P&gt;&lt;P&gt;Is there any benefit of LEA over log exporter?&lt;/P&gt;&lt;P&gt;Is Log Exporter a better alternative and why?&lt;/P&gt;&lt;P&gt;Is there an official Check Point position on the future of these two technologies?&lt;/P&gt;&lt;P&gt;Has anyone else run into this issue and what was your section / Why??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 14:31:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84093#M80360</guid>
      <dc:creator>dantlitz</dc:creator>
      <dc:date>2020-05-04T14:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84095#M80361</link>
      <description>&lt;P&gt;I refer you that the following post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Logging-and-Reporting/Log-Exporter-vs-OPSEC-LEA/td-p/65738" target="_blank"&gt;https://community.checkpoint.com/t5/Logging-and-Reporting/Log-Exporter-vs-OPSEC-LEA/td-p/65738&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 14:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84095#M80361</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2020-05-04T14:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84150#M80362</link>
      <description>&lt;P&gt;For clarity, I want to explicitly emphasize:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Check Point's recommendation for exporting logs is to use LogExporter&lt;/STRONG&gt;, not LEA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has better performance, stability and continues to get new features and capabilities.&lt;/P&gt;
&lt;P&gt;Specifically for Splunk, it also has much better integration and a very cool Check Point Splunk App with views to better visualize Check Point log data.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 06:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84150#M80362</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2020-05-05T06:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84157#M80363</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;...Has anyone else run into this issue and what was your section / Why?? ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running log exporter and it really matches our requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running multiple instances to multiples destinations works fine. Performance is good. Easy implementation compared to LEA or CPlogToSyslog&lt;/P&gt;&lt;P&gt;Only drawback (perhaps fixed meanwhile) is that the filter origin does not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 07:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84157#M80363</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2020-05-05T07:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84161#M80364</link>
      <description>&lt;P&gt;Great news (S_E).&lt;BR /&gt;Happy to hear you like our new log-Exporter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Origin field filter should work.&lt;/P&gt;
&lt;P&gt;Which version/build are you using?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;cpvinfo $EXPORTERDIR/log_exporter&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;cpvinfo $EXPORTERDIR/targets/&amp;lt;your_exporter_name&amp;gt;/log_exporter&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 07:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84161#M80364</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-05-05T07:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84164#M80365</link>
      <description>hi,&lt;BR /&gt;atached is the version.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;cpvinfo $EXPORTERDIR/log_exporter&lt;BR /&gt;** Version info attributes of '/opt/CPrt-R80.30/log_exporter/log_exporter' **&lt;BR /&gt;&lt;BR /&gt;Type = executable&lt;BR /&gt;Name = log_indexer&lt;BR /&gt;Module Name = log_indexer&lt;BR /&gt;Build Number = 993000017&lt;BR /&gt;Major Release = NGX&lt;BR /&gt;Minor Release = heat_main&lt;BR /&gt;Release Number = 5.0.5&lt;BR /&gt;Version Name = NGX&lt;BR /&gt;Interface Version = 0&lt;BR /&gt;Implementation Version = 6&lt;BR /&gt;Internal Name = log_indexer&lt;BR /&gt;Configuration = linux50/release.static&lt;BR /&gt;Comments = NULL&lt;BR /&gt;Company Name = Check Point Software Technologies LTD.&lt;BR /&gt;Legal Copyright = (c) 2005-2009 Copyright Check Point Software Technologies Ltd&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 05 May 2020 08:00:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84164#M80365</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2020-05-05T08:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84165#M80366</link>
      <description>&lt;P&gt;&lt;STRONG&gt;cpinfo -y all&lt;/STRONG&gt; (for JHF version) too, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 08:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84165#M80366</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-05-05T08:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84166#M80367</link>
      <description>cpinfo -y all | grep Take&lt;BR /&gt;&lt;BR /&gt;This is Check Point CPinfo Build 914000191 for GAIA&lt;BR /&gt;Local host is not a Gateway&lt;BR /&gt;HOTFIX_R80_30_JUMBO_HF_MAIN Take: 50&lt;BR /&gt;HOTFIX_R80_30_JUMBO_HF_MAIN Take: 50&lt;BR /&gt;</description>
      <pubDate>Tue, 05 May 2020 08:05:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84166#M80367</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2020-05-05T08:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84174#M80368</link>
      <description>&lt;P&gt;new Filtering feature for log-exporter is only supported from JHF_t&lt;STRONG&gt;107&lt;/STRONG&gt; onwards on R80.30.&lt;/P&gt;
&lt;P&gt;Please install latest R80.30-JHF (t&lt;STRONG&gt;191&lt;/STRONG&gt; currently as of 05.05.20).&lt;BR /&gt;&lt;A style="font-family: inherit; background-color: #ffffff;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk153152&amp;amp;partition=General&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk153152&amp;amp;partition=General&amp;amp;product=Security&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from log-exporter sk (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=General&amp;amp;product=SmartEvent" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=General&amp;amp;product=SmartEvent&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Filtering: choose what to export based on field values.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(Note: Filtering ability is integrated to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk153152" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.30&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;since Take_&lt;STRONG&gt;107&lt;/STRONG&gt;, and to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk137592" target="_blank" rel="noopener"&gt;Jumbo Hotfix Accumulator for R80.20&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;since Take_103.)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 09:26:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84174#M80368</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-05-05T09:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84852#M80369</link>
      <description>&lt;P&gt;Log exporter works great. One caveat you have to be aware of is that the log exporter configuration seems to be blown away with version upgrades. We have a standalone log server separate from the management station. When we upgraded from R80.20 to R80.30 the log exporter configs were overwritten. Same problem occurs with your SSH configuration. If you want to change the SSH port from something other than 22, the changes you make to /etc/ssh/sshd_config are overwritten.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 16:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84852#M80369</guid>
      <dc:creator>John_Tomasetti</dc:creator>
      <dc:date>2020-05-11T16:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84854#M80370</link>
      <description>&lt;P&gt;It‘s possible to include log exporter config in systembackup following&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk124093" target="_blank" rel="noopener"&gt;How to include the configuration of Log Exporter in system backup&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or simple backup the target directory following&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk127653" target="_blank" rel="noopener"&gt;How to backup and restore Log Exporter configuration on upgrades to &lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I would prefer LogExporter over LEA, less CPU usage, very good filtering options and some really nice integration for a lot of the common log systems.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 16:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/84854#M80370</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-05-11T16:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/85656#M80371</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I will be happy to understand why the origin filter is not working, it should work.&lt;/P&gt;
&lt;P&gt;How did you configure it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/85656#M80371</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2020-05-18T12:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: LEA vs Log exporter to send to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/85657#M80372</link>
      <description>&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30395"&gt;@dantlitz&lt;/a&gt; - Check Point's and also Splunk's recommendation is to use Log Exporter. We also released brand new Splunk application that works with the Log exporter format.&lt;BR /&gt;</description>
      <pubDate>Mon, 18 May 2020 12:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LEA-vs-Log-exporter-to-send-to-splunk/m-p/85657#M80372</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2020-05-18T12:54:28Z</dc:date>
    </item>
  </channel>
</rss>

