<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What happened to loguid/UUid in syslog of new Quantum Spark? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/193527#M9545</link>
    <description>&lt;P&gt;Thanks for sharing! good to know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2023 00:19:45 GMT</pubDate>
    <dc:creator>Tom_Hinoue</dc:creator>
    <dc:date>2023-09-26T00:19:45Z</dc:date>
    <item>
      <title>What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182990#M9000</link>
      <description>&lt;P&gt;What happened to loguid/UUid in syslog of new Quantum Spark?&lt;/P&gt;
&lt;P&gt;In R77.20.87 for 700/1400 appliances there was the UUid field which could be used to correlate the delta logs.&lt;/P&gt;
&lt;P&gt;In the new versions there is no loguid or equivalent field. This means it is impossible to correlate a lot of information, such as the office mode IP of a user that connected to Remote Access VPN.&lt;/P&gt;
&lt;P&gt;This was a huge step backwards. The details of the logs have improved, but without this field to allow correlation the logs are useless.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 21:05:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182990#M9000</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2023-06-01T21:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182994#M9001</link>
      <description>&lt;P&gt;What code version?&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20406"&gt;@Amir_Ayalon&lt;/a&gt;&amp;nbsp;are you familiar with this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 22:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182994#M9001</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T22:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182998#M9002</link>
      <description>&lt;P&gt;R81.10.XX&lt;/P&gt;
&lt;P&gt;I still haven't tested the newest build from last month, but all the previous ones had this ussue.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 22:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/182998#M9002</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2023-06-01T22:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/186738#M9204</link>
      <description>&lt;P&gt;R81.10.07 is also affected.&lt;/P&gt;
&lt;P&gt;Very frustrating, because log rate to SMP is limited to 10000/hour, which is very low, leaving huge gaps in logs.&lt;/P&gt;
&lt;P&gt;Also retention is less than a month.&lt;/P&gt;
&lt;P&gt;Plus I can't export from SMP to a SIEM.&lt;/P&gt;
&lt;P&gt;So exporting syslog was the best way to have a better log retention, which is is a MUST even for small organizations today due to new regulations.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 18:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/186738#M9204</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2023-07-18T18:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/193522#M9544</link>
      <description>&lt;P&gt;I received a solution from TAC a few days ago.&lt;/P&gt;
&lt;P&gt;This solution does not survive upgrades and they still haven't confirmed if it will be made default in the next builds.&lt;/P&gt;
&lt;P&gt;Here is the procedure to enable this field:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Access vis SSH to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;/opt/fw1/conf/log_fields.C&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Search for&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;:field_name (uuid)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Change:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;:application_display_mode&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;(none)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:application_name (FWLog)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;To:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;:application_display_mode&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(own_column)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:application_name (FWLog)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;Then run&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;sfwd_restart&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 22:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/193522#M9544</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2023-09-25T22:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: What happened to loguid/UUid in syslog of new Quantum Spark?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/193527#M9545</link>
      <description>&lt;P&gt;Thanks for sharing! good to know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 00:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/What-happened-to-loguid-UUid-in-syslog-of-new-Quantum-Spark/m-p/193527#M9545</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2023-09-26T00:19:45Z</dc:date>
    </item>
  </channel>
</rss>

