<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LogExporter Filters in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208749#M34583</link>
    <description>&lt;P&gt;&lt;STRONG&gt;As mentioned in&amp;nbsp;sk122323,&amp;nbsp;filtering works only&amp;nbsp;&lt;SPAN&gt;for Action / Blade / Origin fields. Not sure if it is possible to filter out logs with respect to log messages.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2024 11:30:17 GMT</pubDate>
    <dc:creator>NiladriSarkar</dc:creator>
    <dc:date>2024-03-14T11:30:17Z</dc:date>
    <item>
      <title>LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208529#M34551</link>
      <description>&lt;P&gt;Hi guys!&lt;BR /&gt;We were testing filters for the LogExporter tool.&lt;BR /&gt;We managed to run some filtering but we have one filter pending, we are trying to filter the sending of firewall status logs, which come from the firewall messages.&lt;BR /&gt;We are editing the configuration file, one of the examples we were able to replicate is to send only audit logs but actually we need to disable only the sending of fw messages logs.&lt;BR /&gt;In the following way we edit the configuration file to meet the auditing requirement.&lt;BR /&gt;log_types&amp;gt;audit&amp;lt;/log_types&amp;gt;&amp;lt;!--all[default]|log|audit/--&amp;gt;&lt;BR /&gt;Can anyone give us some guidance?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 15:44:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208529#M34551</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-03-12T15:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208574#M34558</link>
      <description>&lt;P&gt;That looks like the correct thing to edit (set it to audit instead of all).&lt;BR /&gt;If it's not working after restarting Log Exporter, I suggest a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 00:21:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208574#M34558</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-13T00:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208661#M34575</link>
      <description>&lt;P&gt;Hello PhoneBoy.&lt;BR /&gt;How are you?&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;In case we want to filter only the logs of the firewall messages, do you know how we should edit this configuration file?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 14:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208661#M34575</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-03-13T14:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208674#M34578</link>
      <description>&lt;P&gt;In your original post, you said "&lt;SPAN&gt;we need to disable only the sending of fw messages logs."&lt;BR /&gt;By sending only audit logs, you are filtering out ALL firewall message logs (as none will be sent).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In this response, you said "we want to filter only the logs of the firewall messages" which is a bit different.&lt;BR /&gt;What are your exact requirement(s) here?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Be as specific as possible and include version/JHF of your management.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 15:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208674#M34578</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-13T15:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208688#M34581</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello PhoneBoy.&lt;BR /&gt;Previously we had implemented the auditlog filter successfully.&lt;BR /&gt;Actually we need to see all the firewall logs, only excluding the fw messages, but we could not achieve it.&lt;BR /&gt;The management version is R81.20 and the JHF is take 10.&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 15:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208688#M34581</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-03-13T15:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208708#M34582</link>
      <description>&lt;P&gt;I don't understand what "fw messages" you are referring to.&lt;BR /&gt;Can you provide specific examples, preferably with a full log card (with sensitive details redacted)?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 22:24:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208708#M34582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-13T22:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208749#M34583</link>
      <description>&lt;P&gt;&lt;STRONG&gt;As mentioned in&amp;nbsp;sk122323,&amp;nbsp;filtering works only&amp;nbsp;&lt;SPAN&gt;for Action / Blade / Origin fields. Not sure if it is possible to filter out logs with respect to log messages.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208749#M34583</guid>
      <dc:creator>NiladriSarkar</dc:creator>
      <dc:date>2024-03-14T11:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208793#M34587</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hi PhoneBoy.&lt;BR /&gt;The logs we refer to would be the following based on the following SK:&amp;nbsp;&amp;nbsp; sk144192&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="field.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24868i1C1AFFAE5F9A3F49/image-size/large?v=v2&amp;amp;px=999" role="button" title="field.JPG" alt="field.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 16:43:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208793#M34587</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-03-14T16:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: LogExporter Filters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208806#M34590</link>
      <description>&lt;P&gt;So you do NOT want logs that have something in this field?&lt;BR /&gt;Maybe something like the following in your &amp;lt;filters&amp;gt; stanza of&amp;nbsp;$EXPORTERDIR/targets/&amp;lt;Name of Log Exporter Configuration&amp;gt;/conf/FilterConfiguration.xml:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;    &amp;lt;field name="fw_messages" operator="and"&amp;gt;&lt;BR /&gt;       &amp;lt;value operation="eq"&amp;gt;&amp;lt;/value&amp;gt;
    &amp;lt;/field&amp;gt;&lt;/PRE&gt;
&lt;P&gt;Otherwise, I suggest contacting the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 19:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/LogExporter-Filters/m-p/208806#M34590</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-14T19:51:18Z</dc:date>
    </item>
  </channel>
</rss>

