- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Has anyone used Log Exporter to export logs to LogRhythm? I have a Check Point managment server that is also the log server running R80.20. I've configured Log Exporter and am sending logs to LogRhythm using the CEF format. However, LogRhythm says they cannot parse the logs. Has anyone else run into this problem and found a solution?
Thanks.
We were told by LR support that the only supported method is via OPSEC LEA. They said they are working on Log Exporter support, though no date was given. Very disappointing.
We did successfully get this going with LEA, however the events per second are massive and we don't seem to be getting any Threat Prevention logs. We are currently working on filtering events at the LR collector and will soon be looking into where those TP logs are at. We are not in a good position at the moment with these two products working together.
Another issue to keep an eye on with Log Exporter in general is that with R80.20/30 you cannot filter what is exported. I'm keeping my fingers crossed that this is worked out by the time LR gets around to supporting it.
There was a post here a bit ago about log exporter being updated to add filtering capabilities.
SK122323
I think you are referring to the post announcing initial filtering support. If you look under the Installation section of that same KB it explicitly states filtering for R80.20 & R80.30 is not yet supported.
Does anyone know if Log Exporter support has been added by LogRhythm? If so, any example log_exporter configs for LogRhythm you could share?
Hey Lari,
LogRhythm is now supported by Log Exporter.
All you need to do is to download the hotfix package and install it using CPUSE.
The package can be found in SK122323.
Regarding the deployment command, please type:
cp_log_export add name <exporter_name> target-server <logrhythm_server_ip> target-port <port_number> protocol <tcp/udp> format logrhythm read-mode semi-unified
After that, please run:
cp_log_export start name <exporter_name>
Let me know if you have any issues with it,
Shay
Thanks Shay!
Hello Shayhi
We wish to do an Integration of Log Rhythm with r80.40 MGMT, is it directly supported by the new gaia without a hotfix as the is now hotfix for r80.40
Hi Reuben,
Log Exporter integration with LogRhythm is already part of R80.40 - no hotfix is required.
Shay
Hi @Shay_Hibah ,
And for R80.10, is there any chance of Log Exporter integration with LogRhythm?
I see there are Hotfixes available for this integration with R80.20 and R80.30, but not for R80.10 hence my question.
Thanks and regards,
Joao
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 42 | |
| 26 | |
| 14 | |
| 12 | |
| 10 | |
| 10 | |
| 10 | |
| 9 | |
| 9 |
Thu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Thu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY