<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 Syslog Exporter in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37075#M97153</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/41883"&gt;Hugo van der Kooij&lt;/A&gt;&amp;nbsp;-&amp;nbsp;&amp;nbsp;Any comment that refers to stroopwafels gets a thumbs up in my book &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Aug 2018 20:35:49 GMT</pubDate>
    <dc:creator>phlrnnr</dc:creator>
    <dc:date>2018-08-03T20:35:49Z</dc:date>
    <item>
      <title>R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37042#M97120</link>
      <description>&lt;P&gt;Via Check Point Support you get a Syslog exporter for SIEM applications for R80.10 Managment.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Which allows an easy and secure method for exporting CP logs over syslog. Exporting can be done in few standard protocols and formats.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Log Exporter supports:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Splunk&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Arcsight&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;RSA&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;LogRhythm&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;QRadar&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;McAfee&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Log Exporter is a multi-threaded daemon service, running on a log server. Each log that is written on the log server is read by the log exporter daemon, transformed into the desired format and mapping, and then sent to the end target.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Installation on R80.10 Jumbo Hotfix Take 56 or higher.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;Syntax:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white; margin: 7.5pt 0cm .0001pt 0cm;"&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;# &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #333333;"&gt;cp_log_export add name &amp;lt;name&amp;gt; [domain-server &amp;lt;domain-server&amp;gt;] target-server &amp;lt;target-server&amp;gt; target-port &amp;lt;target-port&amp;gt; protocol &amp;lt;(udp|tcp)&amp;gt; [optional arguments]&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="background: white; margin: 7.5pt 0cm .0001pt 0cm;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="width: 775px;"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="border: 1pt solid #dddddd; background: #f0f0f0 none repeat scroll 0% 0%; padding: 5.25pt 11.25pt 5.25pt 7.5pt; width: 157px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 13px;"&gt;&lt;STRONG&gt;Command Name&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 592px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;Command Description&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;add&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Deploy a new Check Point logs exporter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;set&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Updates an exporter's configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;delete&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Removes an exporter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;show&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Prints an exporter's current configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;status&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Shows an exporter's overview status.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;start&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Starts an exporter process&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;stop&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Stops an exporter process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;restart&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Restarts an exporter process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 157px;"&gt;
&lt;P&gt;&lt;SPAN&gt;reexport&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="border-color: currentcolor #dddddd #dddddd currentcolor; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 5.25pt 7.5pt; width: 592px;"&gt;
&lt;P&gt;&lt;SPAN&gt;Resets the current position, and re-exports all logs per the configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; color: #333333;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728" target="_blank" rel="noopener" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3"&gt;Heiko&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 20:13:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37042#M97120</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-20T20:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37043#M97121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where can I get the installation package?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37043#M97121</guid>
      <dc:creator>Pablo_Montega</dc:creator>
      <dc:date>2018-03-19T16:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37044#M97122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Heiko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you've had a chance to use this tool, please advise if it is possible to:&lt;/P&gt;&lt;P&gt;1. Create separate processes for individual gateways writing to the log server?&lt;/P&gt;&lt;P&gt;2. Resolve gateway names before shipping logs to the destination SIEM for the "Origin" fields?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 17:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37044#M97122</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-19T17:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37045#M97123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are planning to release this tool more generally very VERY soon &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37045#M97123</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-19T18:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37046#M97124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In witch hotfix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 18:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37046#M97124</guid>
      <dc:creator>christian_konne</dc:creator>
      <dc:date>2018-03-19T18:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37047#M97125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The official release:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323"&gt;Logs Exporter - Check Point Logs Export&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To answer your question about "which hotfix" &lt;A href="https://community.checkpoint.com/migrated-users/56471"&gt;christian konner&lt;/A&gt;‌, it's installed over a R77.30/R80.10 management/log server (not gateway) with a recent jumbo hotfix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 15:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37047#M97125</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-20T15:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37048#M97126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can install multiple instances of the log exporter but you cannot separate&amp;nbsp;them by gateways.&lt;/P&gt;&lt;P&gt;The tool reads from the log files (such as fw.log) in your $FWDIR/log directory.&amp;nbsp;&lt;BR /&gt;There are some filtering capabilities, but for the first release, they are mostly focused on key (field) based filters and not value based filters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can filter by 'action' but not by 'accept'/'drop'.&lt;/P&gt;&lt;P&gt;We plan to add more advanced filtering capabilities in future releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 17:16:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37048#M97126</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-03-21T17:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37049#M97127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any plans to re-introduce syslog output directly from gateways, the r77.30 style?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 17:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37049#M97127</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T17:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37050#M97128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you referring&amp;nbsp;to the OPSEC LEA tool?&lt;BR /&gt;If so, I personally am not aware of any such plans to refresh it, but as far as I know, that tool still exists in R80.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new log exporting tool&amp;nbsp;is a direct replacement for the CPLogToSyslog tool. We will be retiring the CPLogToSyslog tool, but I don't know of any plan to retire other tools (such as the OPSEC LEA tool).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 17:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37050#M97128</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-03-21T17:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37051#M97129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the tool is very helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two customers who use it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you say something about how it's gonna be included in the next HFA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Little note:&lt;BR /&gt;The Syslog entry contains firewall rules and thread rules in one line. So some fields have the same name, we have the problem that we cannot index the fields in LogRythm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 17:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37051#M97129</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-21T17:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37052#M97130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Heiko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The plan at this point in time is to have the tool directly integrated into R80.20 (no hotfix needed).&lt;/P&gt;&lt;P&gt;Regarding a future R80.10 HFA integration - at this point in time we have not yet reached a decision on this subject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to your point on LogRhythm - it's true that there are many instances where fields will be sent more than once.&lt;BR /&gt;Sometimes it will be the same field (that is, both instances will have identical information) and sometimes it will be different fields, such as in the case of multiple layers (each layer will have an action field).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We plan to address the former to some degree in the next log exporter release, but the later is inherent to the way our logs are built. I don't think there is any feasible way to resolve this while still keeping all the relevant data in the log.&lt;/P&gt;&lt;P&gt;Those fields appear twice because they represent data which appears twice (like the above example, of one action per layer).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been in contact with LogRhythm, and they are aware of the new tool, and I also know that they have been working on it from their end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I cannot speak for them and am not privy to the details of how/if they plan to address this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 18:05:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37052#M97130</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-03-21T18:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37053#M97131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I am talking about R77.30 add-on:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk87560" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk87560"&gt;How to configure R77.30 Security Gateway on Gaia OS to send FireWall logs to an external Syslog server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 19:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37053#M97131</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T19:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37054#M97132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&amp;nbsp;Yonatan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx for this info.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 19:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37054#M97132</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-03-21T19:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37055#M97133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I've used the CPLogToSyslog package to export the check point logs (based on the cplogtostosyslog rules) to an external syslog server (Extreme Networks Management server) for automate the process for block ip address to the edge of the networks via ExtremeControl NAC.&lt;/P&gt;&lt;P&gt;Now seems that the new method described above is compatible only with some SIEM, but is not general as the previous one, and most important is not possible to define rules for filter was is important to export to the SIEM.&lt;/P&gt;&lt;P&gt;Is this true?&lt;/P&gt;&lt;P&gt;How is possible to know more and test the new tool for see if is still possible to integrate with the Extreme Management syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Antonio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 08:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37055#M97133</guid>
      <dc:creator>ANTONIO_OPROMO1</dc:creator>
      <dc:date>2018-03-22T08:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37056#M97134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323"&gt;&lt;EM&gt;sk122323 Logs Exporter - Check Point Logs Export&lt;/EM&gt;&lt;/A&gt;&amp;nbsp; says that &lt;SPAN style="font-size: 15px; font-family: arial,helvetica,sans-serif;"&gt;Log Exporter supports:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;SIEM applications: Splunk\Arcsight\RSA\LogRhythm\QRadar\McAfee\rsyslog\ng-syslog and any other SIEM application that can run a syslog agent.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Protocols: syslog over TCP or UDP.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Formats: Syslog, CEF, LEEF, Generic.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Security: Mutual authentication TLS.The ability to export logs/audit or both.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Filter out (don't export) firewall connections logs.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 10:17:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37056#M97134</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-22T10:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37057#M97135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;when will be supported the filter out of all the blades (Threat Emulation, IPS, ThreatAV, etc...)?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:07:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37057#M97135</guid>
      <dc:creator>ANTONIO_OPROMO1</dc:creator>
      <dc:date>2018-03-22T14:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37058#M97136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Antonio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We plan to address this gap in a future release.&lt;/P&gt;&lt;P&gt;I don't have any information about what exactly the next release will contain nor when it will be released.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a log exporter guide in another post that covers this and many other questions.&lt;/P&gt;&lt;P&gt;You can find it at&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/7248"&gt;Log Exporter guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you'll find it helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 17:46:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37058#M97136</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-03-22T17:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37059#M97137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounded too good.&lt;/P&gt;&lt;P&gt;On my lab R80.10 with T91 it fails towork as it seems to get in a pickle about permissions.&lt;/P&gt;&lt;P&gt;This showed up in&amp;nbsp;/opt/CPrt-R80/log_exporter/targets/SYSLOG/log/log_indexer.elg:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[log_indexer 27834 4139846544]@fwmgmt[3 Apr 14:03:10] SyslogUDPSender::sendPacket - failed to send packet: &amp;lt;30&amp;gt;Tue Apr 3 14:03:10 CheckPoint Syslog started&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[log_indexer 27834 4129356688]@fwmgmt[3 Apr 14:03:10] SyslogUDPSender::connec - failed to send initial message with handler to [loghost(-1):514]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I initiated this with:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[log_indexer 27834 4139846544]@fwmgmt[3 Apr 14:03:10] SyslogUDPSender::sendPacket - failed to send packet: &amp;lt;30&amp;gt;Tue Apr 3 14:03:10 CheckPoint Syslog started&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;[log_indexer 27834 4129356688]@fwmgmt[3 Apr 14:03:10] SyslogUDPSender::connec - failed to send initial message with handler to [loghost(-1):514]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The host loghost is known as object and it is present in /etc/hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other syslog traffic from GAIA works without a problem. ..... (come to think of this. Might this be the issue?)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 12:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37059#M97137</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-04-03T12:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37060#M97138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hugo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a known issue that stems from an attempt to improve the interface (an attempt which sadly backfired...).&lt;BR /&gt;The original parameter name was 'target-ip'. It was changed based on customer feedback to 'target-server', but the backend stayed the same - expecting an IP-address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add to this the fact that we didn't implement a verification mechanism on the input (to make sure it's a valid IP address) and we have a bug.&lt;/P&gt;&lt;P&gt;We already have a task for this and it will be addressed in the next release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now, the simple fix is to use an IP-address for the 'target-server' parameter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 14:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37060#M97138</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-04-03T14:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Syslog Exporter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37061#M97139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you also discussed this with AlienVault? You still have a partnership with them, yes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-10-Syslog-Exporter/m-p/37061#M97139</guid>
      <dc:creator>rmsource_dotcom</dc:creator>
      <dc:date>2018-04-12T13:55:42Z</dc:date>
    </item>
  </channel>
</rss>

