<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring syslogs to SIEM for Spark SMB devices in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248479#M12599</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We currently have dozens of Quantum Spark devices in the field and looking at a few comprehensive SIEM/SOAR/SOC solutions to enable comprehensive coverage across our clients environments.&lt;/P&gt;&lt;P&gt;Without purchasing Smart-1 for these clients (required for Check Point MDR integration), are we able to send syslogs to an external/internal collector (e.g., Adlumin collector, Huntress Agent)?&lt;/P&gt;&lt;P&gt;If this is possible, how is this achieved? Is it via disabling cloud services and then CLI? In your opinion, what is the down sides to disabling cloud services apart from managing firmware upgrades (currently via Infinity), policies etc.&lt;/P&gt;&lt;P&gt;I hope that makes sense and thanks for any assistance/guidance in advance.&lt;/P&gt;</description>
    <pubDate>Fri, 09 May 2025 04:57:23 GMT</pubDate>
    <dc:creator>drkmtr</dc:creator>
    <dc:date>2025-05-09T04:57:23Z</dc:date>
    <item>
      <title>Configuring syslogs to SIEM for Spark SMB devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248479#M12599</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We currently have dozens of Quantum Spark devices in the field and looking at a few comprehensive SIEM/SOAR/SOC solutions to enable comprehensive coverage across our clients environments.&lt;/P&gt;&lt;P&gt;Without purchasing Smart-1 for these clients (required for Check Point MDR integration), are we able to send syslogs to an external/internal collector (e.g., Adlumin collector, Huntress Agent)?&lt;/P&gt;&lt;P&gt;If this is possible, how is this achieved? Is it via disabling cloud services and then CLI? In your opinion, what is the down sides to disabling cloud services apart from managing firmware upgrades (currently via Infinity), policies etc.&lt;/P&gt;&lt;P&gt;I hope that makes sense and thanks for any assistance/guidance in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 04:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248479#M12599</guid>
      <dc:creator>drkmtr</dc:creator>
      <dc:date>2025-05-09T04:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring syslogs to SIEM for Spark SMB devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248526#M12602</link>
      <description>&lt;P&gt;Exporting security logs via syslog is your only option.&lt;BR /&gt;Note it is not possible to change the format the logs are sent in, which might be problematic for some solutions to ingest.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 17:05:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248526#M12602</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-09T17:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring syslogs to SIEM for Spark SMB devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248571#M12617</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;You should be able to send logs to syslog server while keeping cloud services.&lt;BR /&gt;This can be done under Logs and Monitoring -&amp;gt; External Log Servers -&amp;gt; Syslog Servers.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 11 May 2025 05:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/248571#M12617</guid>
      <dc:creator>sigal</dc:creator>
      <dc:date>2025-05-11T05:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring syslogs to SIEM for Spark SMB devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/250663#M12771</link>
      <description>&lt;P&gt;Thank you to everyone that responded.&lt;/P&gt;&lt;P&gt;This was very easy and a perfect solution. I have configured External Log Servers -&amp;gt; Syslog Servers and added the IP and Port of the Huntress agent, which works seamlessly.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 05:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Configuring-syslogs-to-SIEM-for-Spark-SMB-devices/m-p/250663#M12771</guid>
      <dc:creator>drkmtr</dc:creator>
      <dc:date>2025-06-05T05:26:32Z</dc:date>
    </item>
  </channel>
</rss>

