<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integrating SandBlast Mobile and security information and event management (SIEM) system in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Integrating-SandBlast-Mobile-and-security-information-and-event/m-p/3471#M26</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This functionality enables the forwarding of all the Check Point SandBlast Mobile security and system alerts as they are generated and presented in the dashboard, to any standard Syslog Server in Syslog format. The Syslog will include all data available in the dashboard "Events &amp;amp; Alerts" tab. In addition Check Point's R&amp;amp;D added specific integration to ArcSight with support for ArcSight Common Event Format (CEF).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The data that can be sent to SIEM includes the following fields:&lt;/P&gt;&lt;P&gt;Event Server Timestamp&lt;/P&gt;&lt;P&gt;DeviceAlert Event&lt;/P&gt;&lt;P&gt;EventType&lt;/P&gt;&lt;P&gt;Signature&lt;/P&gt;&lt;P&gt;RiskLevel&lt;/P&gt;&lt;P&gt;DeviceOwner&lt;/P&gt;&lt;P&gt;DeviceNumber&lt;/P&gt;&lt;P&gt;DeviceType&lt;/P&gt;&lt;P&gt;DeviceID&lt;/P&gt;&lt;P&gt;Event ID&lt;/P&gt;&lt;P&gt;Event Client Timestamp&lt;/P&gt;&lt;P&gt;SBM Dashboard URL&lt;/P&gt;&lt;P&gt;DeviceEmail&lt;/P&gt;&lt;P&gt;DeviceOSLevel&lt;/P&gt;&lt;P&gt;DeviceModel&lt;/P&gt;&lt;P&gt;DeviceRiskLevel&lt;/P&gt;&lt;P&gt;SBM Client Version&lt;/P&gt;&lt;P&gt;Device Location&lt;/P&gt;&lt;P&gt;Device MDM ID&lt;/P&gt;&lt;P&gt;APP Threat summary&lt;/P&gt;&lt;P&gt;APP SHA256&lt;/P&gt;&lt;P&gt;App version&lt;/P&gt;&lt;P&gt;App repackaged&lt;/P&gt;&lt;P&gt;NetworkCertificate&lt;/P&gt;&lt;P&gt;NetworkCaptive&lt;/P&gt;&lt;P&gt;Devicerooted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information, please contact Check Point's Local Security Engineer or the regional Mobile Security expert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 May 2017 08:01:59 GMT</pubDate>
    <dc:creator>Daniel_Dor</dc:creator>
    <dc:date>2017-05-23T08:01:59Z</dc:date>
    <item>
      <title>Integrating SandBlast Mobile and security information and event management (SIEM) system</title>
      <link>https://community.checkpoint.com/t5/Mobile/Integrating-SandBlast-Mobile-and-security-information-and-event/m-p/3471#M26</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This functionality enables the forwarding of all the Check Point SandBlast Mobile security and system alerts as they are generated and presented in the dashboard, to any standard Syslog Server in Syslog format. The Syslog will include all data available in the dashboard "Events &amp;amp; Alerts" tab. In addition Check Point's R&amp;amp;D added specific integration to ArcSight with support for ArcSight Common Event Format (CEF).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The data that can be sent to SIEM includes the following fields:&lt;/P&gt;&lt;P&gt;Event Server Timestamp&lt;/P&gt;&lt;P&gt;DeviceAlert Event&lt;/P&gt;&lt;P&gt;EventType&lt;/P&gt;&lt;P&gt;Signature&lt;/P&gt;&lt;P&gt;RiskLevel&lt;/P&gt;&lt;P&gt;DeviceOwner&lt;/P&gt;&lt;P&gt;DeviceNumber&lt;/P&gt;&lt;P&gt;DeviceType&lt;/P&gt;&lt;P&gt;DeviceID&lt;/P&gt;&lt;P&gt;Event ID&lt;/P&gt;&lt;P&gt;Event Client Timestamp&lt;/P&gt;&lt;P&gt;SBM Dashboard URL&lt;/P&gt;&lt;P&gt;DeviceEmail&lt;/P&gt;&lt;P&gt;DeviceOSLevel&lt;/P&gt;&lt;P&gt;DeviceModel&lt;/P&gt;&lt;P&gt;DeviceRiskLevel&lt;/P&gt;&lt;P&gt;SBM Client Version&lt;/P&gt;&lt;P&gt;Device Location&lt;/P&gt;&lt;P&gt;Device MDM ID&lt;/P&gt;&lt;P&gt;APP Threat summary&lt;/P&gt;&lt;P&gt;APP SHA256&lt;/P&gt;&lt;P&gt;App version&lt;/P&gt;&lt;P&gt;App repackaged&lt;/P&gt;&lt;P&gt;NetworkCertificate&lt;/P&gt;&lt;P&gt;NetworkCaptive&lt;/P&gt;&lt;P&gt;Devicerooted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information, please contact Check Point's Local Security Engineer or the regional Mobile Security expert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 08:01:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Integrating-SandBlast-Mobile-and-security-information-and-event/m-p/3471#M26</guid>
      <dc:creator>Daniel_Dor</dc:creator>
      <dc:date>2017-05-23T08:01:59Z</dc:date>
    </item>
  </channel>
</rss>

