<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What log events can CheckPoint Blades produce? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/What-log-events-can-CheckPoint-Blades-produce/m-p/12747#M2073</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As part of our corporate security monitoring initiatives we need to review all the possible log messages that can be produced by the platform across all the main blades e.g. VPN, IPS, URL Filtering, FW, Application Control etc. We currently feed all events in to our own SIEM and SOC and we require information of all possible events that can be produced by the Checkpoint Platform to the level of detail such as that from vendors like Cisco e.g. &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Nov 2017 16:02:43 GMT</pubDate>
    <dc:creator>Roland_Eschenbu</dc:creator>
    <dc:date>2017-11-17T16:02:43Z</dc:date>
    <item>
      <title>What log events can CheckPoint Blades produce?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-log-events-can-CheckPoint-Blades-produce/m-p/12747#M2073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As part of our corporate security monitoring initiatives we need to review all the possible log messages that can be produced by the platform across all the main blades e.g. VPN, IPS, URL Filtering, FW, Application Control etc. We currently feed all events in to our own SIEM and SOC and we require information of all possible events that can be produced by the Checkpoint Platform to the level of detail such as that from vendors like Cisco e.g. &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Nov 2017 16:02:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-log-events-can-CheckPoint-Blades-produce/m-p/12747#M2073</guid>
      <dc:creator>Roland_Eschenbu</dc:creator>
      <dc:date>2017-11-17T16:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: What log events can CheckPoint Blades produce?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/What-log-events-can-CheckPoint-Blades-produce/m-p/12748#M2074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a couple of different types of log messages:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Syslog from the OS:&amp;nbsp;&lt;A class="link-titled" href="http://downloads.checkpoint.com/dc/download.htm?ID=24459" title="http://downloads.checkpoint.com/dc/download.htm?ID=24459" rel="nofollow noopener noreferrer" target="_blank"&gt;Check Point Gaia Syslog Messages Reference Guide&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;The security logs: These are typically imported via LEA.&amp;nbsp;Much of the&amp;nbsp;information we make available via LEA is here: &lt;A href="https://community.checkpoint.com/docs/DOC-2186" target="_blank"&gt;LEA Fields&lt;/A&gt;‌&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe we have a consolidated list of every message that can appear.&lt;/P&gt;&lt;P&gt;I know the LEA document is out of date (it's from 2014).&lt;/P&gt;&lt;P&gt;I believe this is being addressed as part of the LogOut project mentioned here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/7996-re-is-there-a-document-that-list-all-the-possible-values-for-the-action-column-that-i-can-have-in-the-log-for-every-different-blade" target="_blank"&gt;https://community.checkpoint.com/message/7996-re-is-there-a-document-that-list-all-the-possible-values-for-the-action-column-that-i-can-have-in-the-log-for-every-different-blade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/What-log-events-can-CheckPoint-Blades-produce/m-p/12748#M2074</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:03:05Z</dc:date>
    </item>
  </channel>
</rss>

