<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send log from Checkpoint moreover Opsec LEA in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29509#M1195</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use central management, you can&amp;nbsp;use Log Exporter (check&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=General&amp;amp;product=SmartEvent"&gt;sk122323&lt;/A&gt;) or connect&amp;nbsp;using the &lt;A href="https://splunkbase.splunk.com/app/3197/"&gt;Splunk Check Point addon&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also send syslog to a log server directly from&amp;nbsp;SMB appliances in both locally and centrally managed SMBs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78081_external-logs.PNG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Feb 2019 14:02:05 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2019-02-01T14:02:05Z</dc:date>
    <item>
      <title>How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29508#M1194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Hi All&amp;nbsp; &amp;nbsp;I would like to know how to send log moreover opseclea&amp;nbsp;?&amp;nbsp;such as Syslog&amp;nbsp;also if send from Syslog&amp;nbsp; should add plug-in or add-on or not , could you please suggest to me&amp;nbsp; Firmware R77.20&amp;nbsp; &amp;nbsp;The logging server&amp;nbsp; is Splunk&amp;nbsp; &amp;nbsp;Thank you&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 09:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29508#M1194</guid>
      <dc:creator>Pattarachai_Kho</dc:creator>
      <dc:date>2019-02-01T09:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29509#M1195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use central management, you can&amp;nbsp;use Log Exporter (check&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122323&amp;amp;partition=General&amp;amp;product=SmartEvent"&gt;sk122323&lt;/A&gt;) or connect&amp;nbsp;using the &lt;A href="https://splunkbase.splunk.com/app/3197/"&gt;Splunk Check Point addon&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also send syslog to a log server directly from&amp;nbsp;SMB appliances in both locally and centrally managed SMBs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78081_external-logs.PNG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 14:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29509#M1195</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-02-01T14:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29510#M1196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI R77.20 Can install Log export&amp;nbsp; plug-in?&amp;nbsp; Thank you&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 10:46:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29510#M1196</guid>
      <dc:creator>Pattarachai_Kho</dc:creator>
      <dc:date>2019-02-02T10:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29511#M1197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Log Exporter is only available from R77.30 and not available for locally managed SMB appliances.&lt;/P&gt;&lt;P&gt;The syslog support will only get device logs (not security logs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot to my knowledge, configure a LEA connection between an SMB appliance and Splunk.&lt;/P&gt;&lt;P&gt;You&amp;nbsp;can configure a LEA connection with a Check Point log server and configure Splunk to pull from that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29511#M1197</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-02T17:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29512#M1198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can install Log Export or use LEA on a R77.30 or R80.X security management server which manages a SMB appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If locally managed, you have to send Syslog directly from the appliance as shown in the screenshot. No support for LEA then.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 00:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29512#M1198</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-02-04T00:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29513#M1199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thank for answer I have a little&amp;nbsp;bit question now I have to integrate&amp;nbsp;send a log from mgmt with opseclea application to Splunk server but I have found an issue about the Splunk&amp;nbsp;server on window base is support opsec lea or not .&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 03:09:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29513#M1199</guid>
      <dc:creator>Pattarachai_Kho</dc:creator>
      <dc:date>2019-02-04T03:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29514#M1200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are pulling the logs from a Check Point management/log server R77.30 and above, use Log Exporter: &lt;A href="https://community.checkpoint.com/message/23971"&gt;Log Exporter - Splunk Integration Update&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;This does not require LEA at all as it uses syslog.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 11:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29514#M1200</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-04T11:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29515#M1201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌&amp;nbsp; Limitation of Syslog&amp;nbsp;can get log such as firewall log&amp;nbsp; or just device&amp;nbsp; log&amp;nbsp; if use log exporter&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 07:58:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29515#M1201</guid>
      <dc:creator>Pattarachai_Kho</dc:creator>
      <dc:date>2019-02-05T07:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29516#M1202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will get the security logs into splunk.&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;For more information see this discussion:&amp;nbsp;&lt;/SPAN&gt;&lt;A _jive_internal="true" class="" data-containerid="2013" data-containertype="14" data-objectid="10286" data-objecttype="1" href="https://community.checkpoint.com/thread/10286-new-splunk-app-for-check-point-logs" style="color: #6d6e71; background-color: #ffffff; border: 0px; padding: 1px 0px 1px calc(12px + 0.35ex);"&gt;*New* Splunk App for Check Point Logs&lt;/A&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 11:56:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29516#M1202</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-05T11:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to send log from Checkpoint moreover Opsec LEA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29517#M1203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can&amp;nbsp;send all the security logs you seen in SmartLog with Log Exporter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The advantage is that now MGMT is actively sending logs to Splunk, whereas with LEA Splunk has to actively collects logs from MGMT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 15:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-send-log-from-Checkpoint-moreover-Opsec-LEA/m-p/29517#M1203</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-02-05T15:20:10Z</dc:date>
    </item>
  </channel>
</rss>

