<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do not match The number of logs in the GUI and the SIEM device. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/105996#M8426</link>
    <description>&lt;P&gt;Can you provide some precise examples of logs that aren't showing on the SIEM?&lt;BR /&gt;This might be better handled via a TAC case.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Dec 2020 01:53:24 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-12-21T01:53:24Z</dc:date>
    <item>
      <title>Do not match The number of logs in the GUI and the SIEM device.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/105994#M8425</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working to change the SIEM equipment linkage method of a customer from OPSEC to Log Exporter.&lt;/P&gt;&lt;P&gt;When I compare the logs of Smartconsole and the logs of SIEM, there are too many differences.&lt;/P&gt;&lt;P&gt;For example, The Smart console log generates about 5000 drop logs per second.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, only about 300 drop logs are visible for Siem equipment logs.&lt;/P&gt;&lt;P&gt;There is a difference of more than 10 times and I do not know the cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The linked server is Archisight 6.9 / smartconnector 7.15 and The architecture of the customer is as follows.&lt;/P&gt;&lt;P&gt;1.Management Server (R80.20, Take 127)&lt;BR /&gt;2.Log Server (R80.20, Take 127)&lt;BR /&gt;3.VRRP Gateway (R80.10, Take 249) - Firewall, IPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the log export information set to the customer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="export_show.png" style="width: 290px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9838iFF6D16988A7C87E3/image-size/large?v=v2&amp;amp;px=999" role="button" title="export_show.png" alt="export_show.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="filter_configuration.PNG" style="width: 594px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9839iFEBF460FF6C77DBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="filter_configuration.PNG" alt="filter_configuration.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Due to the large amount of logs, it is really difficult to compare the number of packets.&lt;/P&gt;&lt;P&gt;What do I need to check to fix the above symptoms?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 01:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/105994#M8425</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2020-12-21T01:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Do not match The number of logs in the GUI and the SIEM device.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/105996#M8426</link>
      <description>&lt;P&gt;Can you provide some precise examples of logs that aren't showing on the SIEM?&lt;BR /&gt;This might be better handled via a TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 01:53:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/105996#M8426</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-21T01:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Do not match The number of logs in the GUI and the SIEM device.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106023#M8430</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We only compared the number of drop logs of Siem equipment and GUI Smartconsole. Due to the problem of time, it was difficult to check further, so I could not check the contents of inconsistent logs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 09:36:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106023#M8430</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2020-12-21T09:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Do not match The number of logs in the GUI and the SIEM device.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106054#M8433</link>
      <description>&lt;P&gt;You should get a similar number of logs but you’re also only sending Firewall + IPS logs to the SIEM so there may be drops by additional blades you’re not seeing.&lt;BR /&gt;In any case, I recommend a TAC case to investigate.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 16:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106054#M8433</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-21T16:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Do not match The number of logs in the GUI and the SIEM device.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106163#M8447</link>
      <description>&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The blades used by the firewall are Firewall and IPS.&lt;/P&gt;&lt;P&gt;It is logically difficult to understand what gets deleted by other blades.&lt;/P&gt;&lt;P&gt;I will submit the case to the TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 10:08:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Do-not-match-The-number-of-logs-in-the-GUI-and-the-SIEM-device/m-p/106163#M8447</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2020-12-22T10:08:51Z</dc:date>
    </item>
  </channel>
</rss>

