- CheckMates
- :
- Products
- :
- Infinity Global Services
- :
- Events
- :
- Combine Log Exporter filters
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Combine Log Exporter filters
Hi guys!
We are looking to implement two combined filters for log exporter.
On one side we have the following filter that we want to apply:
# cp_log_export set name "name" filter-blade-in TP
and on the other hand we also want to export to the server the logs of the audit type.
Is there a way to combine both?
Thank you.
- Labels:
-
Logging
-
Management
- Tags:
- LogExporter
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe this is the only way to achieve this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to confirm what you're intending, you want to send both audit logs (all of them) and Security Logs that are for a specific blade?
In this case, you may need to create two connections to the same server, one that just sends audit logs (no filter) and one that has the specific filter for security logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Phoneboy.
Thank you for your reply
We currently apply a filter for Threat prevention blades using the following filter
#cp_log_export set name qradar filter-blade-in TP
As you say we should generate another configuration in parallel to the target server that bears another name different from "qradar" and have applied the filter to send only audit logs?
Regards!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe this is the only way to achieve this.
