<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog not forwarding action in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177604#M29605</link>
    <description>&lt;P&gt;The action field is not sent with every log.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk144192" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk144192&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2023 17:45:48 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-06T17:45:48Z</dc:date>
    <item>
      <title>Syslog not forwarding action</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177535#M29598</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have configured a syslog server on R81.10. The logs are forwarding but do not have action in them . The destination is a rhel server with syslog agent running&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please let me know what all need to be checked here&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers appreciated&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CEF:0|Check Point|SmartDefense|Check Point|IPS|SIPVicious Security Scanner|High|cp_severity=High cs2Label=Protection ID cs2=asm_dynamic_prop_SC_SIPVICIOUS cs3Label=Protection Type cs3=IPS cs4Label=Protection Name cs4=SIPVicious Security Scanner deviceDirection=2 flexNumber1Label=Confidence flexNumber1=9 flexNumber2Label=Performance Impact flexNumber2=8 flexString2Label=Attack Information flexString2=SIPVicious Security Scanner msg=Scanner Enforcement Violation rt=1680679718000 loguid={0x9fsdf6ec6,0xdsfdb,0xf8cfcb06,0xbsdf99} origin=132.6.99.180 originsicname=CN\=CHN-New-CP-DW-3,O\=PU-MEZ-CHKPTMGMT-01.napesorg.com.qibhes sequencenum=8842 version=3 description_url=SC_SIPVICIOUS_help.html dst=192.168.2.1 product=SmartDefense smartdefense_profile=Optimized src=81.14.123.112&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 11:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177535#M29598</guid>
      <dc:creator>nikufellow</dc:creator>
      <dc:date>2023-04-06T11:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog not forwarding action</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177551#M29601</link>
      <description>&lt;P&gt;What log exporter settings are you using?&lt;/P&gt;
&lt;P&gt;Namely:&amp;nbsp;&lt;SPAN&gt;format, read-mode, protocol, encryption&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;How else have you verified that the action isn't being sent?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 12:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177551#M29601</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-06T12:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog not forwarding action</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177604#M29605</link>
      <description>&lt;P&gt;The action field is not sent with every log.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk144192" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk144192&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 17:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-not-forwarding-action/m-p/177604#M29605</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-06T17:45:48Z</dc:date>
    </item>
  </channel>
</rss>

