<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exporting Check Point logs over syslog (LogExporter) with Log Server (CP) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38410#M94021</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="color: #222222; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="color: #000000;"&gt;Requirement:&lt;/SPAN&gt; Exporting Check Point logs over Syslog (LogExporter) to SIEM.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Dedicated Log server (CP) with R77.30 GAIA OS&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 01:&lt;/SPAN&gt;&amp;nbsp;Check the current Hotfix install on Log server (CP)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Using CLI: installed_jumbo_take and cpinfo&amp;nbsp;-y all&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Using WebUI:&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;"Status and Actions"&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp; section.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 02:&lt;/SPAN&gt;&amp;nbsp;If take_338 or above is exit then skip this step (step 02) or else follow the below process&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:-&amp;nbsp;Open the WebUI of Log Serer (CP) then go to the&amp;nbsp;"Status and Actions"&amp;nbsp; and import the HOTFIX package then&amp;nbsp;verify&amp;nbsp;and then&amp;nbsp;install&amp;nbsp;the package.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:- For Latest HotFix and installation, refer&amp;nbsp;&lt;SPAN style="color: #000000;"&gt;sk106162,&lt;SPAN style="background-color: #ffffff;"&gt;sk92449&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="text-decoration: underline; font-size: 15px;"&gt;Hotfix take_338&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Link:&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=72663" title="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=72663"&gt;Jumbo_HotFix_take_338&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Verify the MD5 value&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt;&amp;nbsp;Reboot is required&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 03:&lt;/SPAN&gt;&amp;nbsp;After installation of jumbo hotfix needs to install the below HOTFIX.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;Check_Point_R77.30_Log_Exporter_T25_sk122323_FULL.tgz&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt; &amp;nbsp; &amp;nbsp;&lt;SPAN style="text-decoration: underline;"&gt;Link:&lt;/SPAN&gt;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62126" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62126"&gt;R77.30 Log Exporter T30&lt;/A&gt;&amp;nbsp;(R77.30)&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline; color: #000000;"&gt;R80.10 Log Exporter T41 sk122323&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&amp;nbsp; Link:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62128" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62128"&gt;R80.10 Log Exporter T41&lt;/A&gt;&amp;nbsp;(R80.10)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Verify the MD5 value&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt;&amp;nbsp;Reboot is required&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:-&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;Open the WebUI of Log Server&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;then go to the&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;"Status and Actions"&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp; and import the HOTFIX package then&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;verify&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;and then&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;install&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;the package.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;:- Refer&amp;nbsp;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;sk92449&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;for HotFix Installation using CPUSE or legacy CLI method.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 04:&lt;/SPAN&gt;&amp;nbsp;Open the CLI of Log Server (CP) server.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;Below two command required to execute.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ff9900; text-decoration: underline;"&gt;1st:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;cp_log_export add name &amp;lt;name&amp;gt; [domain-server &amp;lt;domain-server&amp;gt;] target-server &amp;lt;target-server&amp;gt; target-port &amp;lt;target-port&amp;gt; protocol &amp;lt;(udp|tcp)&amp;gt; format &amp;lt;(syslog)|(cef)&amp;gt; [optional arguments]&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;EXAMPLE : &lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px; color: #3366ff;"&gt;cp_log_export add name &lt;STRONG style="color: #222222;"&gt;&lt;SPAN style="color: #0000ff;"&gt;ArcSight&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;target-server 192.168.10.6 target-port 514 protocol tcp format syslog&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;Name:-&amp;nbsp;Any name example:&amp;nbsp;&lt;STRONG&gt;ArcSight&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #ffffff; font-size: 15px; "&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&lt;A data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://192.168.10.5/&amp;amp;source=gmail&amp;amp;ust=1531982527885000&amp;amp;usg=AFQjCNG4G0By2APVyQlFOIkYUwMR7LyOAA" href="http://192.168.10.5/" style="color: #1155cc;" target="_blank"&gt;192.168.10.5&lt;/A&gt;: Log server (Checkpoint)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&lt;A data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://192.168.10.6/&amp;amp;source=gmail&amp;amp;ust=1531982527885000&amp;amp;usg=AFQjCNETdhGnOU319AlkM_M2YmPQJenvkw" href="http://192.168.10.6/" style="color: #1155cc;" target="_blank"&gt;192.168.10.6&lt;/A&gt;: SIEM &lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px; font-family: monospace;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ff9900; text-decoration: underline;"&gt;2nd:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;cp_log_export&amp;nbsp;&amp;nbsp;&amp;lt;command-name&amp;gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;EXAMPLE:&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffffff;"&gt;cp_log_export&lt;/SPAN&gt;&amp;nbsp;start&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;stop /&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;status&lt;/SPAN&gt;&amp;nbsp; /&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;restart&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 05:&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;verify by running&amp;nbsp;&lt;/SPAN&gt;tcpdump&lt;SPAN style="font-size: 15px;"&gt;&amp;nbsp;command.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;EXAMLE:&lt;/SPAN&gt;-&amp;nbsp;&amp;nbsp;tcpdump&amp;nbsp;-nni eth0 port '514'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt; Need to configure from SIEM side as well.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt; Jumbo&amp;nbsp;Hotfix may you take the latest one as per the new release, my case I am using take_338&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Refer&amp;nbsp;SK:&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;sk122323 for more details.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;NOTE:&lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;On&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;&amp;nbsp;R80.20&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;onwards no need to install any additional HotFix, latest jumbo take is enough.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;DIV style="font-size: small;"&gt;&lt;DIV style="background-color: #fefefe; font-size: small;"&gt;&lt;SPAN style="font-size: 15px; font-family: Verdana, sans-serif;"&gt;#Chinmaya Naik&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2018 07:17:22 GMT</pubDate>
    <dc:creator>Chinmaya_Naik</dc:creator>
    <dc:date>2018-07-18T07:17:22Z</dc:date>
    <item>
      <title>Exporting Check Point logs over syslog (LogExporter) with Log Server (CP)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38410#M94021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="color: #222222; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="color: #000000;"&gt;Requirement:&lt;/SPAN&gt; Exporting Check Point logs over Syslog (LogExporter) to SIEM.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Dedicated Log server (CP) with R77.30 GAIA OS&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 01:&lt;/SPAN&gt;&amp;nbsp;Check the current Hotfix install on Log server (CP)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Using CLI: installed_jumbo_take and cpinfo&amp;nbsp;-y all&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Using WebUI:&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;"Status and Actions"&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp; section.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 02:&lt;/SPAN&gt;&amp;nbsp;If take_338 or above is exit then skip this step (step 02) or else follow the below process&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:-&amp;nbsp;Open the WebUI of Log Serer (CP) then go to the&amp;nbsp;"Status and Actions"&amp;nbsp; and import the HOTFIX package then&amp;nbsp;verify&amp;nbsp;and then&amp;nbsp;install&amp;nbsp;the package.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:- For Latest HotFix and installation, refer&amp;nbsp;&lt;SPAN style="color: #000000;"&gt;sk106162,&lt;SPAN style="background-color: #ffffff;"&gt;sk92449&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="text-decoration: underline; font-size: 15px;"&gt;Hotfix take_338&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Link:&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=72663" title="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=72663"&gt;Jumbo_HotFix_take_338&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Verify the MD5 value&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt;&amp;nbsp;Reboot is required&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 03:&lt;/SPAN&gt;&amp;nbsp;After installation of jumbo hotfix needs to install the below HOTFIX.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;Check_Point_R77.30_Log_Exporter_T25_sk122323_FULL.tgz&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt; &amp;nbsp; &amp;nbsp;&lt;SPAN style="text-decoration: underline;"&gt;Link:&lt;/SPAN&gt;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62126" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62126"&gt;R77.30 Log Exporter T30&lt;/A&gt;&amp;nbsp;(R77.30)&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline; color: #000000;"&gt;R80.10 Log Exporter T41 sk122323&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&amp;nbsp; Link:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62128" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=62128"&gt;R80.10 Log Exporter T41&lt;/A&gt;&amp;nbsp;(R80.10)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE&lt;/SPAN&gt;: Verify the MD5 value&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt;&amp;nbsp;Reboot is required&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;:-&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;Open the WebUI of Log Server&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;then go to the&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;"Status and Actions"&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp; and import the HOTFIX package then&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;verify&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;and then&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;install&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;the package.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;:- Refer&amp;nbsp;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;sk92449&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;for HotFix Installation using CPUSE or legacy CLI method.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 04:&lt;/SPAN&gt;&amp;nbsp;Open the CLI of Log Server (CP) server.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;Below two command required to execute.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ff9900; text-decoration: underline;"&gt;1st:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;cp_log_export add name &amp;lt;name&amp;gt; [domain-server &amp;lt;domain-server&amp;gt;] target-server &amp;lt;target-server&amp;gt; target-port &amp;lt;target-port&amp;gt; protocol &amp;lt;(udp|tcp)&amp;gt; format &amp;lt;(syslog)|(cef)&amp;gt; [optional arguments]&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;EXAMPLE : &lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px; color: #3366ff;"&gt;cp_log_export add name &lt;STRONG style="color: #222222;"&gt;&lt;SPAN style="color: #0000ff;"&gt;ArcSight&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;target-server 192.168.10.6 target-port 514 protocol tcp format syslog&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;Name:-&amp;nbsp;Any name example:&amp;nbsp;&lt;STRONG&gt;ArcSight&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG style="background-color: #ffffff; font-size: 15px; "&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&lt;A data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://192.168.10.5/&amp;amp;source=gmail&amp;amp;ust=1531982527885000&amp;amp;usg=AFQjCNG4G0By2APVyQlFOIkYUwMR7LyOAA" href="http://192.168.10.5/" style="color: #1155cc;" target="_blank"&gt;192.168.10.5&lt;/A&gt;: Log server (Checkpoint)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&lt;A data-saferedirecturl="https://www.google.com/url?hl=en&amp;amp;q=http://192.168.10.6/&amp;amp;source=gmail&amp;amp;ust=1531982527885000&amp;amp;usg=AFQjCNETdhGnOU319AlkM_M2YmPQJenvkw" href="http://192.168.10.6/" style="color: #1155cc;" target="_blank"&gt;192.168.10.6&lt;/A&gt;: SIEM &lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="background-color: #ffffff; font-size: 15px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px; font-family: monospace;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ff9900; text-decoration: underline;"&gt;2nd:&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;cp_log_export&amp;nbsp;&amp;nbsp;&amp;lt;command-name&amp;gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;EXAMPLE:&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;STRONG&gt;&lt;SPAN style="background-color: #ffffff;"&gt;cp_log_export&lt;/SPAN&gt;&amp;nbsp;start&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;stop /&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;status&lt;/SPAN&gt;&amp;nbsp; /&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;restart&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;Step 05:&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;verify by running&amp;nbsp;&lt;/SPAN&gt;tcpdump&lt;SPAN style="font-size: 15px;"&gt;&amp;nbsp;command.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;EXAMLE:&lt;/SPAN&gt;-&amp;nbsp;&amp;nbsp;tcpdump&amp;nbsp;-nni eth0 port '514'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt; Need to configure from SIEM side as well.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;NOTE:&lt;/SPAN&gt; Jumbo&amp;nbsp;Hotfix may you take the latest one as per the new release, my case I am using take_338&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;Refer&amp;nbsp;SK:&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;sk122323 for more details.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;NOTE:&lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;On&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; color: #000000;"&gt;&amp;nbsp;R80.20&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;onwards no need to install any additional HotFix, latest jumbo take is enough.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV style="background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV style="color: #222222; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;DIV style="font-size: small;"&gt;&lt;DIV style="background-color: #fefefe; font-size: small;"&gt;&lt;SPAN style="font-size: 15px; font-family: Verdana, sans-serif;"&gt;#Chinmaya Naik&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 07:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38410#M94021</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-07-18T07:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting Check Point logs over syslog (LogExporter) with Log Server (CP)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38411#M94022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See this article for R80.10:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/7234"&gt;R80.10 Syslog Exporter&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 10:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38411#M94022</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-07-18T10:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting Check Point logs over syslog (LogExporter) with Log Server (CP)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38412#M94023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm curious, are you saying you used Log Exporter with the syslog format option to send Check Point logs to Alien Vault?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I can tell, their documentation hasn't included this as an option yet so am curious to see if&amp;nbsp;this is&amp;nbsp;working for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.alienvault.com/documentation/usm-anywhere/supported-plugins/configuring-checkpoint-fw1-generic.htm?tocpath=DOCUMENTATION%7CAlienVault%C2%AE%20USM%20Anywhere%E2%84%A2%7CDeployment%20Guide%7CPlugin%20Management%7CSupported%20USM%20Anywhere%20Plugins%20for%20Common%20Data%20Sources%7C_____22" title="https://www.alienvault.com/documentation/usm-anywhere/supported-plugins/configuring-checkpoint-fw1-generic.htm?tocpath=DOCUMENTATION%7CAlienVault%C2%AE%20USM%20Anywhere%E2%84%A2%7CDeployment%20Guide%7CPlugin%20Management%7CSupported%20USM%20Anywhere%20Plugins%20for%20Common%20Data%20Sources%7C_____22"&gt;https://www.alienvault.com/documentation/usm-anywhere/supported-plugins/configuring-checkpoint-fw1-generic.htm?tocpath=D…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2019 04:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38412#M94023</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-01-02T04:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting Check Point logs over syslog (LogExporter) with Log Server (CP)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38413#M94024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Bob i forget to remove&amp;nbsp; "(&lt;SPAN style="font-size: 15px;"&gt;my case Alien Vault)".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Yes you are correct also i check in lab also its not work.&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2019 06:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exporting-Check-Point-logs-over-syslog-LogExporter-with-Log/m-p/38413#M94024</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-01-02T06:33:07Z</dc:date>
    </item>
  </channel>
</rss>

