<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combine Log Exporter filters in Events</title>
    <link>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212584#M11</link>
    <description>&lt;P&gt;I believe this is the only way to achieve this.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2024 14:34:25 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-04-29T14:34:25Z</dc:date>
    <item>
      <title>Combine Log Exporter filters</title>
      <link>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212208#M8</link>
      <description>&lt;P&gt;Hi guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are looking to implement two combined filters for log exporter.&lt;BR /&gt;On one side we have the following filter that we want to apply:&lt;BR /&gt;# cp_log_export set name "name" filter-blade-in TP&lt;/P&gt;&lt;P&gt;and on the other hand we also want to export to the server the logs of the audit type.&lt;BR /&gt;Is there a way to combine both?&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 15:50:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212208#M8</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-04-24T15:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Log Exporter filters</title>
      <link>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212412#M9</link>
      <description>&lt;P&gt;Just to confirm what you're intending, you want to send both audit logs (all of them) and Security Logs that are for a specific blade?&lt;BR /&gt;In this case, you may need to create two connections to the same server, one that just sends audit logs (no filter) and one that has the specific filter for security logs.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 16:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212412#M9</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-26T16:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Log Exporter filters</title>
      <link>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212437#M10</link>
      <description>&lt;P&gt;Hello Phoneboy.&lt;BR /&gt;Thank you for your reply&lt;BR /&gt;We currently apply a filter for Threat prevention blades using the following filter&lt;/P&gt;&lt;P&gt;#cp_log_export set name qradar filter-blade-in TP&lt;/P&gt;&lt;P&gt;As you say we should generate another configuration in parallel to the target server that bears another name different from "qradar" and have applied the filter to send only audit logs?&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 19:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212437#M10</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2024-04-26T19:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Log Exporter filters</title>
      <link>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212584#M11</link>
      <description>&lt;P&gt;I believe this is the only way to achieve this.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:34:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Combine-Log-Exporter-filters/m-p/212584#M11</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-29T14:34:25Z</dc:date>
    </item>
  </channel>
</rss>

