<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlating logs from external log server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31605#M97686</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, thx for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;⁣Sent from my phone​&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Feb 2018 18:01:11 GMT</pubDate>
    <dc:creator>MIRCEA_MITROI1</dc:creator>
    <dc:date>2018-02-23T18:01:11Z</dc:date>
    <item>
      <title>Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31601#M97682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a distributed management/reporting deployment with 1 x R80.10 SmartCenter, 1 x R80.10 SmartEvent and 1 x R77.30.03 SmartEndpoint mgmt server. We have established opsec lea between SmartEvent and Endpoint Server, we receive the logs, the cpstat cpsead looks fine, we can find them under the smartlog, but we cannot find them under the "General Overview" tab. We have also defined "new event" type under the SmartEvent policy, but still couldn't get any correlated endpoint logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be maybe a better idea to send the endpoint server logs to the smartcenter and from there to the smartevent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any idea on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot!&lt;/P&gt;&lt;P&gt;Mircea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 16:25:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31601#M97682</guid>
      <dc:creator>MIRCEA_MITROI1</dc:creator>
      <dc:date>2018-02-21T16:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31602#M97683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of the three management objects (SmartEndpoint, SmartCenter, SmartEvent), which ones have SmartEvent Correlation Unit enabled on them?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 22:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31602#M97683</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-22T22:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31603#M97684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the SmartEvent has the Correlation Unit enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mircea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 07:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31603#M97684</guid>
      <dc:creator>MIRCEA_MITROI1</dc:creator>
      <dc:date>2018-02-23T07:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31604#M97685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are some differences between how R77.x does things and R80.x does things.&lt;/P&gt;&lt;P&gt;Normally I would suggest doing:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110894&amp;amp;partition=General&amp;amp;product=SmartEvent" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110894&amp;amp;partition=General&amp;amp;product=SmartEvent"&gt;How to configure an R80/R80.10 SmartEvent Server with an R77.x Security Management&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But since you're also using R80.10 Management, not sure this is the right answer.&lt;/P&gt;&lt;P&gt;Let me ping R&amp;amp;D &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 17:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31604#M97685</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-23T17:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31605#M97686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, thx for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;⁣Sent from my phone​&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 18:01:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31605#M97686</guid>
      <dc:creator>MIRCEA_MITROI1</dc:creator>
      <dc:date>2018-02-23T18:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31606#M97687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;The default filters of R80.10 SmartEvent "Views" and "Reports" is exclude products from the Endpoint family.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;So maybe the&amp;nbsp;&lt;SPAN&gt;sk118525 is relevant for you.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 15:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31606#M97687</guid>
      <dc:creator>Evgenia_Kritsky</dc:creator>
      <dc:date>2018-02-26T15:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31607#M97688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Evgenia,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, we will give it a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mircea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 19:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31607#M97688</guid>
      <dc:creator>MIRCEA_MITROI1</dc:creator>
      <dc:date>2018-02-26T19:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating logs from external log server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31608#M97689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Evgenia!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the solution. Maybe with R80.20 Endpoint will be fully supported by SmartEvent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx again,&lt;/P&gt;&lt;P&gt;Mircea&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;⁣Sent from my phone​&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 06:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Correlating-logs-from-external-log-server/m-p/31608#M97689</guid>
      <dc:creator>MIRCEA_MITROI1</dc:creator>
      <dc:date>2018-03-02T06:57:58Z</dc:date>
    </item>
  </channel>
</rss>

