Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vinceneil666
Advisor

Sandblast Agent / Mobile, logs.

hi,

Is it really like this, or am I missing something essential here ? 

 

SandBlast Agent Cloud

Use SmartView cloud for reports/logs/views - but ONLY for SandBlast Agent.

As pr feedback from Check Point, it is not yet possible to export this to an excisting log server. (let say you have an on prem enviromet of firewalls etc.)

SandBlast Mobile Cloud

EVENTS still in Beta, and buggy as bugs can get.

As pr feedback from Check Point, it is not yet possible to export this to an excisting log server. (let say you have an on prem enviromet of firewalls etc.)

An option to "show in smartview" is show under "Events and Alerts" - we have yet to see an implementation where this work, allways show "page cannot be displayed.."-with some domain name info etc..

 

So If I have a customer, with a management server on prem, 10-15 firewalls, log servers..etc etc. He will have to pull up 3 different vies to view logs, create reports ..etc ? (one for the as is, one for agent and one for mobile)

6 Replies
PhoneBoy
Admin
Admin

My understanding is that SandBlast Mobile should have an export via syslog function, which could be imported into an existing management server.
Also SandBlast Agent Cloud can export via Log Exporter, but it has to be configured by TAC and isn't meant for a Check Point log server, but a third party SIEM.
Unifying all this is on the roadmap.

Kobie_Bendalak
Employee
Employee

SandBlast Agent supports it already, you can configure it yourself.

Go to SandBlast Agent Management Platform > EndPoint Settings > Export Events.

0 Kudos
PhoneBoy
Admin
Admin

Ah, you learn something new every day 🙂

0 Kudos
Julian_Sanchez
Collaborator

Hello, 

How I can export my logs from Sandblast Agent Cloud to my Security Management on-premise? 

I have SmartEvent and I want to correlate CloudGuardSaaS, Firewalls, and SandblastAgent Cloud

Is the same with log_exporter?

 

0 Kudos
vinceneil666
Advisor

As far as I know, unless they have updated the service recentley, you cant. Only SaaS can export - but the roadmap says it will be available after a while 🙂 

0 Kudos
Kobie_Bendalak
Employee
Employee

You can export events to your on-premise enviorment, be advised it's not a native integration.

You can export your events in the following formats: SYSLOG, CEF, LEEF, SPLUNK.

Go to SBA mgmt. platform > End Point Settings > Export Events

0 Kudos