<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Direct log forwarding from Quantum Spark to on-prem SIEM in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263767#M13480</link>
    <description>&lt;P&gt;Yes, you can send logs directly to a SIEM, but it is done locally on the Spark appliance, not through Smart-1 Cloud.&lt;/P&gt;
&lt;P&gt;Just go to the WebUI and create an external log server and check the system logs and security logs boxes.&lt;/P&gt;
&lt;P&gt;The downside is that the logs sent by Spark are a pain to parse, while Smart-1 cloud will give you a beautiful JSON.&lt;/P&gt;
&lt;P&gt;The upside is that you can send the logs to a local forwarder with a queue/cache and not lose logs in case the internet is down.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Nov 2025 14:08:40 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2025-11-27T14:08:40Z</dc:date>
    <item>
      <title>Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263168#M13447</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;We are currently using multiple Quantum Spark appliances managed by Smart-1 Cloud.&lt;BR /&gt;We are planning to introduce an on-prem SIEM(include syslog feature) in order to perform correlation analysis&lt;BR /&gt;together with logs from our other network devices.&lt;/P&gt;
&lt;P&gt;However, when using the Smart-1 Cloud Log Exporter, log forwarding is subject to&lt;BR /&gt;ingestion-based billing. To avoid additional costs, we would prefer to have the&lt;BR /&gt;Gateway itself send logs directly to our on-prem SIEM server.&lt;/P&gt;
&lt;P&gt;I would like to ask for clarification on the following points:&lt;/P&gt;
&lt;P&gt;1. Under Smart-1 Cloud management, is it possible for a Gateway to send logs&lt;BR /&gt;both to an external SIEM server and to Smart-1 Cloud at the same time?&lt;/P&gt;
&lt;P&gt;2. If direct log forwarding from the Gateway is supported, does it require any&lt;BR /&gt;additional licenses?&lt;/P&gt;
&lt;P&gt;Our intention is to continue using Smart-1 Cloud for management, while forwarding logs&lt;BR /&gt;independently from the Gateway directly to our SIEM.&lt;/P&gt;
&lt;P&gt;If anyone has experience with this setup or detailed knowledge of the official&lt;BR /&gt;specifications, your guidance would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 01:47:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263168#M13447</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2025-11-19T01:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263195#M13449</link>
      <description>&lt;P&gt;Typically configuring a syslog server entry in GAiA OS would yield only local OS logs, security logs come via the Management.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 10:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263195#M13449</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-11-19T10:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263196#M13450</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63380"&gt;@TSOL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe this is what are you looking for &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/CLI/EN/Content/Topics/add-netflow-collector.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Appliances/Quantum_Spark_R82.00.X/CLI/EN/Content/Topics/add-netflow-collector.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 10:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263196#M13450</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-11-19T10:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263328#M13451</link>
      <description>&lt;P&gt;For regular (non-SMB) gateways, there is:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk87560" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk87560&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Note this only gets firewall logs, not logs for other blades.&lt;BR /&gt;Not sure you can set an external syslog server for security logs on a centrally managed SMB.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 15:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263328#M13451</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-11-20T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263329#M13452</link>
      <description>&lt;P&gt;Not sure SIEMs can injest Netflow.&lt;BR /&gt;Also, Netflow only communicates active connections.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 15:41:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263329#M13452</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-11-20T15:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263767#M13480</link>
      <description>&lt;P&gt;Yes, you can send logs directly to a SIEM, but it is done locally on the Spark appliance, not through Smart-1 Cloud.&lt;/P&gt;
&lt;P&gt;Just go to the WebUI and create an external log server and check the system logs and security logs boxes.&lt;/P&gt;
&lt;P&gt;The downside is that the logs sent by Spark are a pain to parse, while Smart-1 cloud will give you a beautiful JSON.&lt;/P&gt;
&lt;P&gt;The upside is that you can send the logs to a local forwarder with a queue/cache and not lose logs in case the internet is down.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 14:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263767#M13480</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2025-11-27T14:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Direct log forwarding from Quantum Spark to on-prem SIEM</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263768#M13481</link>
      <description>&lt;P&gt;In Spark appliances, both system logs and security logs are available. They are Gaia Embedded, a whole different creature.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 14:10:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Direct-log-forwarding-from-Quantum-Spark-to-on-prem-SIEM/m-p/263768#M13481</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2025-11-27T14:10:08Z</dc:date>
    </item>
  </channel>
</rss>

