<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241577#M40335</link>
    <description>&lt;P&gt;The logs should still appear in Smart-1 Cloud, yes.&lt;BR /&gt;The syslog is "in addition to" in this case.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2025 21:05:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-02-18T21:05:47Z</dc:date>
    <item>
      <title>Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241380#M40268</link>
      <description>&lt;P&gt;Hello mates,&lt;BR /&gt;&lt;BR /&gt;A customer needs to send logs to a Syslog Server directly from Security Gateways which are managed by Smart-1 Cloud SMS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where has the "Send logs and alerts to these log servers" table gone inside the Cluster object Logs menu?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In OnPrem deployments to add syslog servers to forward logs directly from the gateways you can double-click the Security Cluster object, then click "Logs" in the left menu tree and add a third party syslog server&amp;nbsp;in the "&lt;STRONG&gt;Send logs and alerts to these log servers&lt;/STRONG&gt;" table.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I can't seem to find this table anymore in the security cluster object which is managed by Smart-1 Cloud SMS.&amp;nbsp;&lt;BR /&gt;Is there any workaround to this or should I use the Log Exporter in the Infinity Portal?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there another way to forward Gateway logs to a syslog&amp;nbsp; server in parallel to the S1C which already receives the logs?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please, also find a screenshot attached with the Log options inside the Cluster object.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241380#M40268</guid>
      <dc:creator>L3on</dc:creator>
      <dc:date>2025-02-17T15:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241388#M40269</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/116777"&gt;@L3on&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My opinion is that, using cp_log_export is much more easier/safer, but oldschool.&lt;/P&gt;
&lt;P&gt;What kind of logs want you to forward? Traffic logs? If yes:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NetFlow Export&amp;nbsp;&lt;/STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk102041" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk102041&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can send logs direcly from the gateway. There are limitations, so start with this chapter.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Q: Cluster object, then click "Logs" in the left menu tree and add a third party syslog server&amp;nbsp;in the "&lt;STRONG&gt;Send logs and alerts to these log servers&lt;/STRONG&gt;" table.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-02-17 16_31_36-Cloud Demo Server [ID_341870930]-R81.20-SmartConsole.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29629iBFA305FC601E378B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-02-17 16_31_36-Cloud Demo Server [ID_341870930]-R81.20-SmartConsole.png" alt="2025-02-17 16_31_36-Cloud Demo Server [ID_341870930]-R81.20-SmartConsole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;or:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-02-17 16_30_21-Gateway Cluster Properties - Corporate-Cluster.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29630i12A6F6B1A403170D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-02-17 16_30_21-Gateway Cluster Properties - Corporate-Cluster.png" alt="2025-02-17 16_30_21-Gateway Cluster Properties - Corporate-Cluster.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241388#M40269</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-17T15:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241392#M40270</link>
      <description>&lt;P&gt;Thanks for the quick response.&amp;nbsp;&lt;BR /&gt;I need to send firewall logs to the syslog at the same time they are being sent to the SMS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241392#M40270</guid>
      <dc:creator>L3on</dc:creator>
      <dc:date>2025-02-17T15:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241397#M40272</link>
      <description>&lt;P&gt;Ok, then the it is simple. You configure a cp_log_export on the SMS, and when the log arrives, it will be sent immediately to the external SYSLOG server.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/CLI/cp_log_export.htm" target="_self"&gt;Here&lt;/A&gt; is the guide, or &lt;A href="https://support.checkpoint.com/results/sk/sk122323" target="_self"&gt;this&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Syntax:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;cp_log_export add name &amp;lt;&lt;EM&gt;Name&lt;/EM&gt;&amp;gt; [domain-server {mds | all}] target-server &amp;lt;&lt;EM&gt;HostName or IP address of Target Server&lt;/EM&gt;&amp;gt; target-port &amp;lt;&lt;EM&gt;Port on Target Server&lt;/EM&gt;&amp;gt; protocol {udp | tcp} format {syslog | splunk |&amp;nbsp;cef | leef | generic | json | logrhythm | rsa} [&amp;lt;&lt;EM&gt;Optional Arguments&lt;/EM&gt;&amp;gt;]&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Akos&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 16:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241397#M40272</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-02-17T16:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241452#M40276</link>
      <description>&lt;P&gt;If gateways are managed by Smart-1 Cloud, logs can only be exported from Infinity Portal using Log Exporter (note this requires a specific SKU).&lt;BR /&gt;You can configure syslog on the gateway as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;suggested, which should send firewall logs (not other blades) as they arrive on the gateway to the configured syslog server.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 23:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241452#M40276</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-17T23:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241470#M40283</link>
      <description>&lt;P&gt;Thank you for reply!&lt;BR /&gt;But with the syslog configuration on the gateway, would the firewall logs still be forwarded to the Smart-1 Cloud SMS as well?&amp;nbsp;&lt;BR /&gt;Or would they be missing from the logging in the Logs&amp;amp;Monitor view in the Infinity Portal?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 07:50:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241470#M40283</guid>
      <dc:creator>L3on</dc:creator>
      <dc:date>2025-02-18T07:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Send logs to additional Syslog Server directly from Security Gateways managed by Smart-1 Cloud</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241577#M40335</link>
      <description>&lt;P&gt;The logs should still appear in Smart-1 Cloud, yes.&lt;BR /&gt;The syslog is "in addition to" in this case.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 21:05:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-logs-to-additional-Syslog-Server-directly-from-Security/m-p/241577#M40335</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-18T21:05:47Z</dc:date>
    </item>
  </channel>
</rss>

