<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S1C forwarding LOGS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269578#M45293</link>
    <description>&lt;P&gt;Sounds like that, yes.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Feb 2026 14:50:44 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-02-03T14:50:44Z</dc:date>
    <item>
      <title>S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269562#M45282</link>
      <description>&lt;P&gt;Hi mates,&lt;BR /&gt;I have a question.&lt;/P&gt;
&lt;P&gt;Is it possible to forward logs to a SIEM using TCP without SSL/TLS when using Smart-1 Cloud?&lt;/P&gt;
&lt;P&gt;According to the documentation, this seems to be supported:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Using-the-Settings.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Using-the-Settings.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However, when I contacted TAC, they advised that it’s better to use TLS.&lt;BR /&gt;I was wondering if anyone has a working TCP (non-SSL) configuration in production.&lt;/P&gt;
&lt;P&gt;Also, does the choice of protocol depend on the specific SIEM being used?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 13:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269562#M45282</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-03T13:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269563#M45283</link>
      <description>&lt;P&gt;When I look at the documentation, it clearly states that both SSL-encrypted forwarding and plain forwarding are supported. &lt;BR /&gt;The choice of protocol, whether TLS, plain or UDP, depends on what your SIEM supports. Tac's statement is, of course, correct. Encrypted transmission should always be preferred to plain text transmission, even if plain text is supported and works.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 13:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269563#M45283</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-03T13:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269564#M45284</link>
      <description>&lt;P&gt;100% right Vincent&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 13:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269564#M45284</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-03T13:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269566#M45285</link>
      <description>&lt;P data-start="65" data-end="290"&gt;We only need to set up this configuration with Tufin, and the Tufin team told us that they support UDP on port 514 and TLS.&lt;BR /&gt;However, as far as I know, we already tried UDP, and it doesn’t seem to be working.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269566#M45285</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-03T14:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269570#M45286</link>
      <description>&lt;P&gt;Did you work like discussed here?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://forum.tufin.com/support/kc/latest/Content/Suite/cp_log-exp_R81.20.htm" target="_blank"&gt;https://forum.tufin.com/support/kc/latest/Content/Suite/cp_log-exp_R81.20.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'm an S1C layman, I'm just trying to brainstorm a little. &lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:27:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269570#M45286</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-03T14:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269572#M45287</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;100% possible. We do it for few customers to siem solution. There is TAC case currently for new CP customer using S1C where we have an issue doing it for tcp protocol, so TAC is working on that. You just do it from the portal itself, see below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33025i45B9823FBE91720E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269572#M45287</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-03T14:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269573#M45288</link>
      <description>&lt;P&gt;Apparently, I wasn't that far off the mark. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269573#M45288</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-03T14:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269574#M45289</link>
      <description>&lt;P&gt;You got it.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/100677"&gt;@RemoteUser&lt;/a&gt;&amp;nbsp;, I know 2 customers where we have this working with tcp/over tls as well. Just not sure this issue we currently have if it is siem or not. TAC guy said he believes it could be log rate problem, but they are still checking it.&lt;/P&gt;
&lt;P&gt;Will update you once we have a solution.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:41:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269574#M45289</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-03T14:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269575#M45290</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182699" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182699&lt;/A&gt;&amp;nbsp;this cloud be a possible solution?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269575#M45290</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-03T14:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269576#M45291</link>
      <description>&lt;P&gt;100%. Sorry, forgot about it. TAC gave us that sk last week as well.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:47:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269576#M45291</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-03T14:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269577#M45292</link>
      <description>&lt;P&gt;ok but since we want to export all the logs of the managment i need to configure this rule on all the policy package of the cma?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:49:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269577#M45292</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-03T14:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269578#M45293</link>
      <description>&lt;P&gt;Sounds like that, yes.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 14:50:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269578#M45293</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-03T14:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269845#M45316</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Were you able to sort this out?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 00:27:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269845#M45316</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T00:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269857#M45319</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;
&lt;P&gt;Yes, Check Point is sending the logs without any issues. It looks like there’s something in between that’s interfering and causing the logs to arrive incompletely at Tufin.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 06:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269857#M45319</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-06T06:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269884#M45326</link>
      <description>&lt;P&gt;I will let you know how we fix the issue we have with new CP customer. TAC is telling us that all on S1C side is fine, but its so weird, because if we change to send logs say using udp and random port, works for few seconds at a time, or 1 minute, then stops.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 11:50:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/269884#M45326</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-06T11:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270165#M45363</link>
      <description>&lt;DIV&gt;
&lt;P&gt;Hi,&lt;BR /&gt;Event Forwarding from the portal also supports TLS (non-SSL) configuration.&lt;/P&gt;
&lt;P&gt;Are there any customers interested in enabling this? If so, we’d be happy to assist and gather feedback.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step 4 in the attached:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding-Push.htm?tocpath=Account%20Settings%7CEvent%20Forwarding%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding-Push.htm?tocpath=Account%20Settings%7CEvent%20Forwarding%7C_____1&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 13:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270165#M45363</guid>
      <dc:creator>AlexVaisberg</dc:creator>
      <dc:date>2026-02-10T13:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270167#M45364</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;We spent many hours troubleshooting this. TAC even verified all was fine on S1C side, nat rule was 100% right, but ended up being that we changed cluster object IP from external to internal, modified link selection, pushed policy, then all worked fine, we can now see logs. Appears logs were being sent over maas tunnel interface for some reason, rather than external, like what happens witt environments where this does work.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 13:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270167#M45364</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-10T13:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270190#M45366</link>
      <description>&lt;P&gt;Hi Bro - whic nat rule ? this ?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182699" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182699&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 15:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270190#M45366</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-10T15:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270192#M45367</link>
      <description>&lt;P&gt;Nope...thats regular rule, Im talking about actual nat rule. In this dst is wan IP of the cluster (VIP) and then dst is log collector.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33130i90BAA6E1A1171679/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 15:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270192#M45367</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-10T15:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: S1C forwarding LOGS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270193#M45368</link>
      <description>&lt;P&gt;Ah, got it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&amp;nbsp;that’s why it seemed strange to me to talk about NAT with that rule &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 15:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/S1C-forwarding-LOGS/m-p/270193#M45368</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-10T15:13:07Z</dc:date>
    </item>
  </channel>
</rss>

