<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending logs to logrhythm in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125304#M23110</link>
    <description>&lt;P&gt;Sorry about the late reply but we have the logexporter configured on the management server to send logs to the logrhythm server, the doubt that the logrhythm team has is how can they check if the logs that they are seeing are from every firewall that are sending logs to the mgmt server? When you say tail how do we check the tail on logrhythm side? Will checking the tail show that logs are being sent from every firewall? Do we have to look for the name of the Firewalls in the tail?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jul 2021 22:30:27 GMT</pubDate>
    <dc:creator>kb1</dc:creator>
    <dc:date>2021-07-29T22:30:27Z</dc:date>
    <item>
      <title>Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124379#M22993</link>
      <description>&lt;P&gt;I have a question regarding sending logs from each firewall (we have multiple firewalls, most running on R80.20, some on R80.40 and a few on do R77) to logrhythm.&lt;/P&gt;&lt;P&gt;Do we have to configure logging on each firewall so that each firewall sends the logs to the logrhythm server or do we have to configure only the management server so that the mgmt server itself can send all the logs that it receives from all the firewalls to logrhythm? We already have the management server configured to send all logs to the logrhythm server and getting reports saying that for a lot of firewalls the logs are not being sent to logrhythm.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 22:06:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124379#M22993</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-07-19T22:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124381#M22994</link>
      <description>&lt;P&gt;The way to do this is via Log Exporter from the Management/Log Server.&lt;BR /&gt;Possible there's a filter configured which is causing some logs not to be sent.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 22:29:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124381#M22994</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-19T22:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124382#M22995</link>
      <description>&lt;P&gt;Thanks for replying and yes log exporter has been configured already on the mgmt server, when you say a filter is configured that prevents some logs from not being sent what do you you exactly mean? As far as I am aware there shouldn't be anything blocking logs from being sent over to logrhythm but I could be wrong, where do I get started on trying to troubleshoot this filter that you are talking about?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 22:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124382#M22995</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-07-19T22:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124383#M22996</link>
      <description>&lt;P&gt;It's part of the Log Exporter configuration.&lt;BR /&gt;Refer to the filtering section here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 22:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124383#M22996</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-19T22:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124386#M22997</link>
      <description>&lt;P&gt;Where did you see the logs are not sent to logrhythm?&lt;/P&gt;&lt;P&gt;Did you try tail on LR side? If there isn't log on LR tail, check the log-exporter config again. It could be log exporter service stopped or something wrong on config...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 00:48:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/124386#M22997</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2021-07-20T00:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125304#M23110</link>
      <description>&lt;P&gt;Sorry about the late reply but we have the logexporter configured on the management server to send logs to the logrhythm server, the doubt that the logrhythm team has is how can they check if the logs that they are seeing are from every firewall that are sending logs to the mgmt server? When you say tail how do we check the tail on logrhythm side? Will checking the tail show that logs are being sent from every firewall? Do we have to look for the name of the Firewalls in the tail?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 22:30:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125304#M23110</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-07-29T22:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125305#M23111</link>
      <description>&lt;P&gt;You have to verify on the LogRhythm side that logs are being received from every gateway by checking to see if you see logs from those gateways.&lt;BR /&gt;Not aware of the specifics on how to do that.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 22:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125305#M23111</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-29T22:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sending logs to logrhythm</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125306#M23112</link>
      <description>&lt;P&gt;Ok I will let them know to check and see what they are seeing on the tail logs, thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 22:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Sending-logs-to-logrhythm/m-p/125306#M23112</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-07-29T22:36:08Z</dc:date>
    </item>
  </channel>
</rss>

