- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello. I am wondering if anyone has experience in working with the filterconfiguration.xml file. We are trying to filter out so we get all logs for certain blades and then only logs with certain severity for other blades. We would like all Identity Awareness, Content, Application Control and URL filtering. Then severity 3 or 4 for Threat, AV, IPS, etc. Below is the config we are trying to use but as soon as we put in the severity we get almost no logs for any blades. I suspect that is because it is applying severity to the other blades which do not have that field. Do we need to put the severity field under each blade that we want only those severity levels?
<filters>
<filterGroup operator="and">
<field name="action" operator="and">
</field>
<field name="origin" operator="and">
</field>
<field name="product" operator="or">
<value operation="eq">Identity Awareness</value>
<value operation="eq">Content Awareness</value>
<value operation="eq">Application Control</value>
<value operation="eq">URL Filtering</value>
</field>
<field name="product" operator="or">
<value operation="eq">Anti-Bot</value>
<value operation="eq">Anti Malware</value>
<value operation="eq">IPS</value>
<value operation="eq">IPS-1</value>
<value operation="eq">SmartDefense</value>
<value operation="eq">Anti-Virus</value>
<value operation="eq">New Anti Virus</value>
<value operation="eq">Anti Virus</value>
<value operation="eq">Threat Extraction</value>
</field>
<field name="severity" operator="and">
<value operation="eq">3</value>
<value operation="eq">4</value>
</field>
</filterGroup>
</filters>
Edited your original post for clarity.
I don't think this will match anything:
<field name="severity" operator="and">
<value operation="eq">3</value>
<value operation="eq">4</value>
</field>
It should be an operator="or" in this case, at least if I'm understanding sk122323 correctly.
Also, everything in the filterGroup must match (e.g. product = X AND severity = Y).
That basically means you'll need to create two different filterGroups (one with the blades you want to send based on priority and one with the blades you want to send irrespective of priority).
Whether you can put that in one filterConfiguration.xml or you'll need to configure a second export to the same server with the other filterConfiguration, I'm not sure.
Edited your original post for clarity.
I don't think this will match anything:
<field name="severity" operator="and">
<value operation="eq">3</value>
<value operation="eq">4</value>
</field>
It should be an operator="or" in this case, at least if I'm understanding sk122323 correctly.
Also, everything in the filterGroup must match (e.g. product = X AND severity = Y).
That basically means you'll need to create two different filterGroups (one with the blades you want to send based on priority and one with the blades you want to send irrespective of priority).
Whether you can put that in one filterConfiguration.xml or you'll need to configure a second export to the same server with the other filterConfiguration, I'm not sure.
Hello @PhoneBoy,
Thank you for your sharing, I am facing an issue regarding the audit log from the smart console by using Log Exporter. Could you help to provide more statements to filter the audit log?
Best Regards,
Ravoth
Hey @Ravoth,
I am forwarding audit logs from our Management Server (shows SmartConsole logins, Web API logins, policy installations, etc) using the following config on the Mgmt:
cp_log_export add name auditlogs.mgmt target-server x.x.x.x target-port 12214 protocol tcp format cef
cp_log_export set name auditlogs.mgmt filter-origin-in "x.x.x.x"
Hey @Ravoth,
I'm pretty sure you would need to use the FieldsMapping.xml to specifically filter the logs you want.
SK122323 gives a detailed explanation of the filtering capabilities in Log Exporter. Also, SK144192 gives a list of fields in the Check Point logs (including Management Server).
Hello, How I can find out which product should I use do I need all or only smart defense is enough? I used Confidence level as well but I am not getting unknow logs which I had before edit the xml file
Depends on what products you have…and what products you want logs sent on.
IPS is somewhat unique in that some protections still show up as SmartDefense (legacy name for IPS-type functionality).
Best to look at the log entries you for sure want and make sure you account for them in the filter configuration.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY