<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Geolocation details in Checkpoint Syslogs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137409#M24530</link>
    <description>&lt;P&gt;Well, dont thank me yet :-). I did ask, but lets see if I get the answer...if this is something he put lots of work into, I cant guarantee he can share it, but I will let you know either way.&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Dec 2021 19:02:14 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-12-29T19:02:14Z</dc:date>
    <item>
      <title>Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137354#M24522</link>
      <description>&lt;P&gt;I have integrated Checkpoint R80.40 with an SIEM tool via log exporter configuration.&lt;/P&gt;&lt;P&gt;SIEM teams is looking for Geo Location information from these syslogs..is it possible to get this information from syslogs ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 12:05:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137354#M24522</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-12-29T12:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137357#M24523</link>
      <description>&lt;P&gt;Are you using geo objects in your access policy?&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Search for src_country / dst_country in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;sk144192 to understand the mappings.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 12:39:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137357#M24523</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-12-29T12:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137362#M24524</link>
      <description>&lt;P&gt;Thanks for the reply.. no i am not using geo objects but i was wondering if any location information can be filtered from syslogs ..like in smartconsole logs we can see a location flag against source and destination IPs&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 13:37:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137362#M24524</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-12-29T13:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137367#M24526</link>
      <description>&lt;P&gt;I am not SIEM guy by any means, but from what I know, dont believe you can do it that way, though I could ask one of my colleagues, as I know he did something even better for a customer.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137367#M24526</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T15:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137390#M24528</link>
      <description>&lt;P&gt;I emailed my colleague your question, so will see what he says.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137390#M24528</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T16:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137407#M24529</link>
      <description>&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 18:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137407#M24529</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-12-29T18:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137409#M24530</link>
      <description>&lt;P&gt;Well, dont thank me yet :-). I did ask, but lets see if I get the answer...if this is something he put lots of work into, I cant guarantee he can share it, but I will let you know either way.&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 19:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137409#M24530</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T19:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Geolocation details in Checkpoint Syslogs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137494#M24548</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8988"&gt;@LostBoY&lt;/a&gt;&amp;nbsp;. This is a response I got from my colleague to your initial question:&lt;/P&gt;
&lt;P&gt;"You can only get external IP and then the SIEM should have the capability to map the IP to country and city name etc. Usually SIEM tools are equipped with GEOIP databases and lookups. Syslog will include only external IPs"&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 02:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geolocation-details-in-Checkpoint-Syslogs/m-p/137494#M24548</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-31T02:18:33Z</dc:date>
    </item>
  </channel>
</rss>

