<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export Logs To LogRhythm using Log Exporter in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72102#M85656</link>
    <description>&lt;P&gt;Does anyone know if Log Exporter support has been added by LogRhythm? If so, any example log_exporter configs for LogRhythm you could share?&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jan 2020 22:08:17 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2020-01-11T22:08:17Z</dc:date>
    <item>
      <title>Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54761#M85652</link>
      <description>&lt;P&gt;Has anyone used Log Exporter to export logs to LogRhythm?&amp;nbsp; I have a Check Point managment server that is also the log server running R80.20.&amp;nbsp; I've configured Log Exporter and am sending logs to LogRhythm using the CEF format.&amp;nbsp; However, LogRhythm says they cannot parse the logs.&amp;nbsp; Has anyone else run into this problem and found a solution?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 19:49:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54761#M85652</guid>
      <dc:creator>MIchael_Hovis</dc:creator>
      <dc:date>2019-05-30T19:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54811#M85653</link>
      <description>&lt;P&gt;We were told by LR support that the only supported method is via OPSEC LEA.&amp;nbsp; They said they are working on Log Exporter support, though no date was given.&amp;nbsp; Very disappointing.&lt;/P&gt;&lt;P&gt;We did successfully get this going with LEA, however the events per second are massive and we don't seem to be getting any Threat Prevention logs.&amp;nbsp; We are currently working on filtering events at the LR collector and will soon be looking into where those TP logs are at.&amp;nbsp; We are not in a good position at the moment with these two products working together.&lt;/P&gt;&lt;P&gt;Another issue to keep an eye on with Log Exporter in general is that with R80.20/30 you cannot filter what is exported.&amp;nbsp; I'm keeping my fingers crossed that this is worked out by the time LR gets around to supporting it.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 14:19:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54811#M85653</guid>
      <dc:creator>Richard_Amos</dc:creator>
      <dc:date>2019-05-31T14:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54816#M85654</link>
      <description>&lt;P&gt;There was a post here a bit ago about log exporter being updated to add filtering capabilities.&lt;/P&gt;&lt;P&gt;SK122323&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323#Filter%20Configuration" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323#Filter%20Configuration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 14:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54816#M85654</guid>
      <dc:creator>Tommy_Forrest</dc:creator>
      <dc:date>2019-05-31T14:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54823#M85655</link>
      <description>&lt;P&gt;I think you are referring to the post announcing initial filtering support.&amp;nbsp; If you look under the Installation section of that same KB it explicitly states filtering for R80.20 &amp;amp; R80.30 is not yet supported.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 19:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/54823#M85655</guid>
      <dc:creator>Richard_Amos</dc:creator>
      <dc:date>2019-05-31T19:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72102#M85656</link>
      <description>&lt;P&gt;Does anyone know if Log Exporter support has been added by LogRhythm? If so, any example log_exporter configs for LogRhythm you could share?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2020 22:08:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72102#M85656</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2020-01-11T22:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72308#M85657</link>
      <description>&lt;P&gt;Hey Lari,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LogRhythm is now supported by Log Exporter.&lt;/P&gt;
&lt;P&gt;All you need to do is to download the hotfix package and install it using CPUSE.&lt;/P&gt;
&lt;P&gt;The package can be found in SK122323.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the deployment command, please type:&lt;/P&gt;
&lt;P&gt;cp_log_export add name &amp;lt;exporter_name&amp;gt; target-server &amp;lt;logrhythm_server_ip&amp;gt; target-port &amp;lt;port_number&amp;gt; protocol &amp;lt;tcp/udp&amp;gt; format logrhythm read-mode semi-unified&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, please run:&lt;/P&gt;
&lt;P&gt;cp_log_export start name &amp;lt;exporter_name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if you have any issues with it,&lt;/P&gt;
&lt;P&gt;Shay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 12:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72308#M85657</guid>
      <dc:creator>Shay_Hibah</dc:creator>
      <dc:date>2020-01-15T12:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72361#M85658</link>
      <description>&lt;P&gt;Thanks Shay!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 19:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/72361#M85658</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2020-01-15T19:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/74310#M85659</link>
      <description>&lt;P&gt;Hello Shayhi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We wish to do an Integration of Log Rhythm with r80.40 MGMT, is it directly supported by the new gaia without a hotfix as the is now hotfix for r80.40&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 10:23:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/74310#M85659</guid>
      <dc:creator>Reuben_W</dc:creator>
      <dc:date>2020-02-06T10:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/74312#M85660</link>
      <description>&lt;P&gt;Hi Reuben,&lt;/P&gt;
&lt;P&gt;Log Exporter integration with LogRhythm is already part of R80.40 - no hotfix is required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shay&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 10:34:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/74312#M85660</guid>
      <dc:creator>Shay_Hibah</dc:creator>
      <dc:date>2020-02-06T10:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/86059#M85661</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8155"&gt;@Shay_Hibah&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;And for R80.10, is there any chance of Log Exporter integration with LogRhythm?&lt;/P&gt;&lt;P&gt;I see there are Hotfixes available for this integration with R80.20 and R80.30, but not for R80.10 hence my question.&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Joao&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 11:22:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/86059#M85661</guid>
      <dc:creator>jrolim</dc:creator>
      <dc:date>2020-05-22T11:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Export Logs To LogRhythm using Log Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/86114#M85662</link>
      <description>Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/46346"&gt;@jrolim&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Unfortunately LogRhythm is not supported on R80.10.&lt;BR /&gt;From R80.20 our infrastructure was changed and we are able to support LogRhythm as well due to this change.&lt;BR /&gt;&lt;BR /&gt;Shay</description>
      <pubDate>Sat, 23 May 2020 11:25:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Logs-To-LogRhythm-using-Log-Exporter/m-p/86114#M85662</guid>
      <dc:creator>Shay_Hibah</dc:creator>
      <dc:date>2020-05-23T11:25:53Z</dc:date>
    </item>
  </channel>
</rss>

