<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding Events to third-party SIEM solutions in Events</title>
    <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223682#M33</link>
    <description>&lt;P&gt;I have read this post couple times but I don't get it to be honest.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2024 18:26:57 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-08-14T18:26:57Z</dc:date>
    <item>
      <title>Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223667#M32</link>
      <description>&lt;P&gt;Received an Email survey from Checkpoint with a link to mailing.checkpoint.com which redirects to some odd sounding hosting service on [an].[gr-wcon].[com] While Checkpoint URL categorization allowed it, Microsoft Smartscreen blocked it.&lt;/P&gt;&lt;P&gt;Assuming this is a legit survey Checkpoint just used a lower reputation survey/hosting service, putting my response here.&lt;/P&gt;&lt;P&gt;Add direct integrations for broader list of 3rd party SIEM's&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ELK Stack&lt;/LI&gt;&lt;LI&gt;Azure Sentinel&lt;/LI&gt;&lt;LI&gt;Google Security Operations SIEM&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 14 Aug 2024 16:08:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223667#M32</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2024-08-14T16:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223682#M33</link>
      <description>&lt;P&gt;I have read this post couple times but I don't get it to be honest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 18:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223682#M33</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-14T18:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223684#M34</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Can&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valeri Loukine (Val) from Checkpoint Checkmates that sent this email provide some context?&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&lt;TABLE border="0" width="100%" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;TABLE border="0" width="100%" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;STRONG&gt;CheckMates&lt;/STRONG&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;We are currently enhancing our&amp;nbsp;&lt;STRONG&gt;Events and Logs&amp;nbsp;&lt;/STRONG&gt;solutions and would like to invite you to collaborate with us in defining the&amp;nbsp;&lt;STRONG&gt;short-term roadmap&lt;/STRONG&gt;. Your expertise and insights will be invaluable in shaping the future direction and ensuring we meet our goals effectively&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your input will help us tailor our solutions to better meet the unique security needs of your organizations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;We greatly appreciate your participation and look forward to your valuable&amp;nbsp;&lt;A class="" href="https://mailing.checkpoint.com/click.html?x=a62e&amp;amp;lc=I2P&amp;amp;mc=k&amp;amp;s=mGQC&amp;amp;u=r&amp;amp;z=GS6F1my&amp;amp;" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;&lt;U&gt;feedback&lt;/U&gt;&lt;/STRONG&gt;&lt;/A&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;STRONG&gt;Val&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Head of CheckMates&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 18:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223684#M34</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2024-08-14T18:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223689#M35</link>
      <description>&lt;P&gt;Ah you want to discuss the e-mail on the community. I filled it in:&amp;nbsp;&lt;SPAN&gt;Your response was submitted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Nothing more I can add so I will leave this thread &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223689#M35</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-14T19:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223690#M36</link>
      <description>&lt;P&gt;Exactly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you also escalate review of the hosting/survey website the link leads to?&amp;nbsp; Doesn't seem to have the best reputation and blocked by other security solutions.&amp;nbsp; Perhaps Checkpoint needs to re-evaluate which hosting/survey platform is used for next communications with customers &amp;amp; community&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:06:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223690#M36</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2024-08-14T19:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223691#M37</link>
      <description>&lt;P&gt;Nop Check Point does not send me a pay check &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:20:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223691#M37</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-14T19:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223716#M38</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25014"&gt;@George_Casper&lt;/a&gt;&amp;nbsp;and all,&lt;BR /&gt;&lt;BR /&gt;We are using a third-party platform to send our community emails. As part of the service, the platform tracks links through redirect domains. One of them, an.gr-wcon.com, is about a week old, and some of the less elaborate security solutions flag it for unknown reputation.&lt;BR /&gt;&lt;BR /&gt;You are right to be prudent and cautious, but in this particular case, you have a false positive flag.&lt;BR /&gt;&lt;BR /&gt;Yes, we raised the issue with the service provider, but as with many false positive security issues, the root cause is mostly out of their control.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I hope this addresses your concerns.&lt;/P&gt;
&lt;P&gt;You can go and fill out the survey at your pleasure, with &lt;A href="https://forms.office.com/pages/responsepage.aspx?id=iVIqYaiJwkWkDfNvrbbTfIkMn1DdSvNCvzryYARaeaVUNjlJMVZYRFhWN0QyVFRPUEg0SVdBSzdMUy4u" target="_self"&gt;this direct link, no redirection&lt;/A&gt;s.&lt;/P&gt;
&lt;P&gt;Just for transparency's sake, we are using Microsoft Forms to collect the responses.&lt;BR /&gt;&lt;BR /&gt;For any further inquiry, please reach out to me directly via email: vloukine@checkpoint.com&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Val&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 07:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223716#M38</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-15T07:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223720#M39</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25014"&gt;@George_Casper&lt;/a&gt;&amp;nbsp;Already address in another comment.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Also,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;is not working for us, at least not yet, lol.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, can we please put this to rest?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:00:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223720#M39</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-15T08:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223722#M40</link>
      <description>&lt;P&gt;Lol&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:01:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223722#M40</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-15T08:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Events to third-party SIEM solutions</title>
      <link>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223788#M41</link>
      <description>&lt;P&gt;Harmony Endpoint is also flagging this domain:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 456px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27258i1516342B612F154F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This is a legitimate email, as is the one I sent earlier regarding &lt;A href="https://checkpoint.zoom.us/webinar/register/8617237309944/WN_liYRiiRWRJ645Xu3QNt-yQ#/registration" target="_blank"&gt;livestreaming the next CheckMates Go podcast episode&lt;/A&gt;&amp;nbsp;that also appears to be triggering this issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 17:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Forwarding-Events-to-third-party-SIEM-solutions/m-p/223788#M41</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-15T17:34:30Z</dc:date>
    </item>
  </channel>
</rss>

