<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector Syslog messages in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232976#M38929</link>
    <description>&lt;P&gt;Yes, in our case the gateway has correctly connected to the IC.&lt;/P&gt;&lt;P&gt;The status shows that the last event sent at 12:11. Can you tell me where on the gateway I can view this event? Or where should the events on the gateway be displayed?&lt;/P&gt;&lt;P&gt;I apologize. Perhaps I could find the answers to these questions in the documentation. But I can't do that yet.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2024 09:22:04 GMT</pubDate>
    <dc:creator>Polina_1</dc:creator>
    <dc:date>2024-11-18T09:22:04Z</dc:date>
    <item>
      <title>Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232929#M38913</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We need to configure Identity Collector to receive information via syslog. We have configured Syslog Parser correctly, we checked in the Test messages field, everything works correctly.&lt;BR /&gt;Then we did everything as described in AdminGuide. But for some reason no events are received.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please tell me where we could have made a mistake in the configuration? How can we see if the messages reach the Identity Collector? Maybe it is a cosmetic error in the status.&lt;BR /&gt;I would be glad to have any information on this topic, as AdminGuide doesn't really cover this in detail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 08:46:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232929#M38913</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-11-16T08:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232930#M38914</link>
      <description>&lt;P&gt;I remember few months ago, in the summer, I was helping a customer who had this issue and TAC discovered it had something to do with the certificate on the server where IC was installed. Btw, also, can you verify all gateways show as connected?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 12:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232930#M38914</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-16T12:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232936#M38916</link>
      <description>&lt;P&gt;Yes, the gateway is correctly connected to the IC.&lt;/P&gt;&lt;P&gt;Could you please elaborate more on what the problem was with the certificate?&lt;/P&gt;&lt;P&gt;Actually I don't even know what to look at to identify the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2024 08:57:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232936#M38916</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-11-17T08:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232945#M38917</link>
      <description>&lt;P&gt;I would have to check my notes, but if you are allowed to, we can do remote and happy to try assist.&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2024 15:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232945#M38917</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-17T15:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232949#M38918</link>
      <description>&lt;P&gt;Just checked the notes I have and their issue was related to gateway not connecting in IC, which yours is, so not the same.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2024 17:10:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232949#M38918</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-17T17:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232976#M38929</link>
      <description>&lt;P&gt;Yes, in our case the gateway has correctly connected to the IC.&lt;/P&gt;&lt;P&gt;The status shows that the last event sent at 12:11. Can you tell me where on the gateway I can view this event? Or where should the events on the gateway be displayed?&lt;/P&gt;&lt;P&gt;I apologize. Perhaps I could find the answers to these questions in the documentation. But I can't do that yet.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 09:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232976#M38929</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-11-18T09:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232980#M38931</link>
      <description>&lt;P&gt;Dont apologize, we are here to help. Yes, thats where you see it. But, here is the question...do you have correct AD info configured under sources? I will take screenshot later and send.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 11:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232980#M38931</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-18T11:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232983#M38933</link>
      <description>&lt;P&gt;We configured the sources as follows. I've attached a screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 12:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232983#M38933</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-11-18T12:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232989#M38936</link>
      <description>&lt;P&gt;That looks right to me. At this point, if you are not seeing any events, you may need to do traffic capture to see why.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 12:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232989#M38936</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-18T12:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232990#M38937</link>
      <description>&lt;P&gt;We have done traffic capture on the server where IC is installed. The required events are received. I have also attached a screenshot.&lt;BR /&gt;We also turned off the firewall on Windows. To exclude the problem in that. But all to no success.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 13:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232990#M38937</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-11-18T13:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232991#M38938</link>
      <description>&lt;P&gt;I meant capture on the firewall. We need to see if fw is having problems communicating properly. Have you done zdebug to see if anything related to IC is getting dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 13:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/232991#M38938</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-18T13:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234575#M39179</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85881"&gt;@Polina_1&lt;/a&gt;&amp;nbsp;Did you manage the resolve the issue? It seems we're having exactly the same issue here.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 10:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234575#M39179</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-12-04T10:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234589#M39183</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No, we didn't succeed in solving that problem.&lt;BR /&gt;We used a Network Access Control (NAC) server as the source of the syslog messages.&lt;BR /&gt;I believe that the IC server expects to receive the following events:&lt;/P&gt;&lt;P&gt;Authentication events - 4624, 4768, 4769, 4770&lt;BR /&gt;Group update events - 4728, 4729, 4732, 4733, 4756, 4757&lt;BR /&gt;Group deletion events - 4730, 4734, 4758&lt;/P&gt;&lt;P&gt;Source: &lt;A href="https://support.checkpoint.com/results/sk/sk108235" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108235&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Our NAC server did not generate any such events. Therefore, our testing ended with a negative result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:31:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234589#M39183</guid>
      <dc:creator>Polina_1</dc:creator>
      <dc:date>2024-12-04T12:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Syslog messages</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234590#M39184</link>
      <description>&lt;P&gt;I see. At this point I wonder if the events are limited to those or not. Admin Guide also mentions the exact same events.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 12:39:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Syslog-messages/m-p/234590#M39184</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-12-04T12:39:57Z</dc:date>
    </item>
  </channel>
</rss>

