<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181024#M30212</link>
    <description>&lt;P&gt;I think that might be by default, but you can confirm for sure with TAC.&lt;/P&gt;</description>
    <pubDate>Mon, 15 May 2023 23:58:58 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-15T23:58:58Z</dc:date>
    <item>
      <title>Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/180996#M30206</link>
      <description>&lt;P&gt;I have configured log exporter to send logs in syslog format to a Splunk SIEM on an R81.10 SMS, which manages 9 security gateways. The Splunk SIEM could detect the hostname of the security gateway which originated the logs in its host field and registered the 9 log sources.&lt;/P&gt;&lt;P&gt;After upgrading to R81.20, the Splunk SIEM sees all logs as originating from the SMS hostname, and can see only one log source. Its host field has the hostname of the SMS and not the hostname of the originating security gateway. The log message includes the SICname of the originating GW, but they would need to re-parse in order to extract it.&lt;/P&gt;&lt;P&gt;Has something changed in the format of log exporter for syslog in R81.20? Or is there a configurable parameter where I can specify the the logs be identified as originating from the security gateway and not the SMS?&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 21:55:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/180996#M30206</guid>
      <dc:creator>Mark_Papworth</dc:creator>
      <dc:date>2023-05-15T21:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181001#M30207</link>
      <description>&lt;P&gt;Funny you mentioned this, cause last week, customer and I were on with TAC troubleshooting something totally unrelated and client mentioned log exporter and they wanted to upgrade mgmt to R81.20 and TAC guy brought this issue up, but I wish I inquired further. Not sure if he only meant this happens if you upgrade mgmt ONLY or gateway as well...sorry mate, I should have asked, but did not.&lt;/P&gt;
&lt;P&gt;Now, he did say possible workaround is to simply issue cp_log_export restart command&lt;/P&gt;
&lt;P&gt;Not sure how long that would work for though.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 22:07:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181001#M30207</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-15T22:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181006#M30208</link>
      <description>&lt;P&gt;Thanks for your prompt reply Andy.&lt;/P&gt;&lt;P&gt;We upgraded mgmt and all gateways to R81.20 and applied the latest JHF also. I believe we tried restarting log export and it didn't help. Maybe I should reach out to TAC and see if it´s a known issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 22:20:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181006#M30208</guid>
      <dc:creator>Mark_Papworth</dc:creator>
      <dc:date>2023-05-15T22:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181009#M30209</link>
      <description>&lt;P&gt;I recommend doing so (especially since an upgrade "broke" it):&amp;nbsp;&lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 22:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181009#M30209</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-15T22:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181013#M30210</link>
      <description>&lt;P&gt;I only found below related to log exporter, but not something you would be concerned about. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said, open TAC case and they can verify.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20920i49D06023780D06FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 22:49:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181013#M30210</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-15T22:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181022#M30211</link>
      <description>&lt;P&gt;The issue seems to have been solved. We simply changed the cp_log_export format from syslog to splunk!&lt;/P&gt;&lt;P&gt;I presume in R81.20 Checkpoint has improved the compatibility with the splunk format, as this didn't work under R81.10.&lt;/P&gt;&lt;P&gt;At the SIEM end they were using a collector called SC4S which received Checkpoint logs in syslog format and converted them to Splunk.&lt;/P&gt;&lt;P&gt;Now they are able to parse the logs sent in Splunk format without issue, although they are still going through SC4S.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 23:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181022#M30211</guid>
      <dc:creator>Mark_Papworth</dc:creator>
      <dc:date>2023-05-15T23:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog exports to Splunk SIEM changed from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181024#M30212</link>
      <description>&lt;P&gt;I think that might be by default, but you can confirm for sure with TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 23:58:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Syslog-exports-to-Splunk-SIEM-changed-from-R81-10-to-R81-20/m-p/181024#M30212</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-15T23:58:58Z</dc:date>
    </item>
  </channel>
</rss>

