<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any API endpoint to retrieve or query raw logs (also suppressed logs) in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108726#M5532</link>
    <description>&lt;P&gt;We have been working with the show-logs API endpoint but suppressed logs are not accessible.&lt;/P&gt;&lt;P&gt;Do you mean that using the log exporter we can export all logs, even suppressed logs?&lt;/P&gt;&lt;P&gt;We integrated the logs with Splunk without luck, the suppressed logs are not being forwarded.&lt;/P&gt;&lt;P&gt;We have followed this integration document &lt;A href="https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm?topic=documents/App_for_Splunk/207353" target="_blank"&gt;https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm?topic=documents/App_for_Splunk/207353&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can the SIEM integration be changed to forward raw logs (also suppressed logs)?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 08:04:54 GMT</pubDate>
    <dc:creator>Oscar_Bernat</dc:creator>
    <dc:date>2021-01-25T08:04:54Z</dc:date>
    <item>
      <title>Is there any API endpoint to retrieve or query raw logs (also suppressed logs)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108544#M5523</link>
      <description />
      <pubDate>Fri, 22 Jan 2021 16:09:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108544#M5523</guid>
      <dc:creator>Oscar_Bernat</dc:creator>
      <dc:date>2021-01-22T16:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any API endpoint to retrieve or query raw logs (also suppressed logs)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108554#M5524</link>
      <description>&lt;P&gt;R80.40 JHF and R81, yes.&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v1.7" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v1.7&lt;/A&gt;&lt;BR /&gt;If you want all logs, you’re better off using something like Log Exporter.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 17:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108554#M5524</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-22T17:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any API endpoint to retrieve or query raw logs (also suppressed logs)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108726#M5532</link>
      <description>&lt;P&gt;We have been working with the show-logs API endpoint but suppressed logs are not accessible.&lt;/P&gt;&lt;P&gt;Do you mean that using the log exporter we can export all logs, even suppressed logs?&lt;/P&gt;&lt;P&gt;We integrated the logs with Splunk without luck, the suppressed logs are not being forwarded.&lt;/P&gt;&lt;P&gt;We have followed this integration document &lt;A href="https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm?topic=documents/App_for_Splunk/207353" target="_blank"&gt;https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm?topic=documents/App_for_Splunk/207353&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can the SIEM integration be changed to forward raw logs (also suppressed logs)?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 08:04:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108726#M5532</guid>
      <dc:creator>Oscar_Bernat</dc:creator>
      <dc:date>2021-01-25T08:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any API endpoint to retrieve or query raw logs (also suppressed logs)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108729#M5533</link>
      <description>&lt;P&gt;As I &lt;A href="https://community.checkpoint.com/t5/Security-Management/What-is-the-impact-of-removing-log-suppression/m-p/108727/highlight/true#M25361" target="_self"&gt;just posted in your other thread&lt;/A&gt;, suppressed logs are suppressed from being written anywhere.&lt;BR /&gt;Which means the logs simply don't exist, no matter how you might want to acquire them.&lt;BR /&gt;If you need those logs, you have to disable log suppression.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 08:15:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/108729#M5533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T08:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any API endpoint to retrieve or query raw logs (also suppressed logs)</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/109251#M5535</link>
      <description>&lt;P&gt;Thanks a lot!!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 07:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Is-there-any-API-endpoint-to-retrieve-or-query-raw-logs-also/m-p/109251#M5535</guid>
      <dc:creator>Oscar_Bernat</dc:creator>
      <dc:date>2021-01-29T07:56:59Z</dc:date>
    </item>
  </channel>
</rss>

