<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs forwarding in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52447#M2069</link>
    <description>&lt;P&gt;I think it is available since R77.20.80.&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2019 17:57:44 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2019-05-02T17:57:44Z</dc:date>
    <item>
      <title>Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51829#M2026</link>
      <description>&lt;P&gt;Can we send &lt;SPAN&gt;Check Point&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;730 Appliance system and security logs to AWS EC2 system directly through syslog configuration ?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 11:19:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51829#M2026</guid>
      <dc:creator>ojuser</dc:creator>
      <dc:date>2019-04-25T11:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51896#M2027</link>
      <description>SMB device logs can be forwarded through syslog.&lt;BR /&gt;Security Logs from SMB can only be forwarded through an OPSEC LEA connection (not syslog).</description>
      <pubDate>Thu, 25 Apr 2019 23:27:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51896#M2027</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-25T23:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51918#M2030</link>
      <description>&lt;P&gt;Any idea how I can configure the logs from CP to AWS EC2 instance through&amp;nbsp;&lt;SPAN&gt;OPSEC LEA. Do I need to configure anything extra as I don't have CP SMS licence in my environment. Please share some details / documents which can be helpful here. Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 03:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51918#M2030</guid>
      <dc:creator>ojuser</dc:creator>
      <dc:date>2019-04-26T03:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51920#M2031</link>
      <description>You would need an SMS to receive the  logs from the 730.&lt;BR /&gt;That SMS could run in AWS using a PAYG license.&lt;BR /&gt;Once on an SMS you could use Log Exporter to send the logs via syslog wherever it needs to go.</description>
      <pubDate>Fri, 26 Apr 2019 05:07:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/51920#M2031</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-26T05:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52283#M2048</link>
      <description>&lt;P&gt;Actually, you CAN export security logs via syslog, but it will be plain UDP syslog, without any security or guarantee of delivery.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, the format is not very friendly and you'd need to customize your own filter.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 20:09:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52283#M2048</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-04-30T20:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52346#M2052</link>
      <description>Pretty sure that's only for OS logs and not Security logs.</description>
      <pubDate>Wed, 01 May 2019 20:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52346#M2052</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-01T20:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52356#M2053</link>
      <description>&lt;P&gt;Not sure what version we started supporting it, but yes includes the option to send security logs. Enable Show obfuscated if needed. As Pedro says not sent securely and will need to parse them to do any reporting on them.&lt;/P&gt;
&lt;P&gt;The central log server may be the better option for both of these reasons.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="syslog-options.jpg" style="width: 509px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1049iAD7114E444EBDF41/image-size/large?v=v2&amp;amp;px=999" role="button" title="syslog-options.jpg" alt="syslog-options.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 23:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52356#M2053</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-05-01T23:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52360#M2055</link>
      <description>&lt;P&gt;Yep, it's been around for a while.&lt;/P&gt;
&lt;P&gt;I am logging to NAS-based syslog in my lab from standalone 1430:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1050i27FB5E0641855BF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 23:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52360#M2055</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-01T23:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52444#M2068</link>
      <description>Well then, I'm happy to be wrong in this case.&lt;BR /&gt;And it must be a relatively recent feature.</description>
      <pubDate>Thu, 02 May 2019 17:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52444#M2068</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-02T17:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Logs forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52447#M2069</link>
      <description>&lt;P&gt;I think it is available since R77.20.80.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 17:57:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Logs-forwarding/m-p/52447#M2069</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-05-02T17:57:44Z</dc:date>
    </item>
  </channel>
</rss>

