Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Explorer

Multi-Domain Server Syslog to CP Log Exporter

Hi,

 

I am currently having an issue where the MDS server syslog is not being exported to our syslog server using Check Point log exporter. Check Point log exporter seems to be working well with exporting received firewall syslog messages but MDS is unable to export the syslog messages.Forwarding to management server is enabled on MDS server webUI. Are there any configurations we are missing out? 

0 Kudos
4 Replies
Highlighted
Champion
Champion

On a GAIA system, like and MDS, you have the option to send Syslog directly to the syslog server.
That being said, here is why you will not get the syslog information from the MDS into any Syslog Forwarder stream:
All syslog forwarders are connected to a specific domain, the MDS itself is not, if it will forward the syslog to a CP domain it will most probably be the Global domain. So when you have a forwarder on the global domain, I really don't know what you will get, all logs for all domains or only these syslogs?
Regards, Maarten
0 Kudos
Highlighted
Explorer

Hi Marteen,

We are able to receive and export Check Point logs that are received in the Smart Console. We are however unable to receive and export syslog messages such as SSH login or WebUI login on the MDS sever.I suspect MDS server syslog is unable to send Check Point logs. I am attempting to use Log exporter to export logs in /var/log/messages but I have no clue about the log_file field parameter inside the targetConfiguration.xml.

 

<source>
<log_files>1</log_files><!-- on-line[default] | read logs from [number] days back (recommended) | specific file name -->
<log_types></log_types><!--all[default]|log|audit/-->
<folder>/var/log</folder><!--$FWDIR/log[default]|specific path-->
<read_mode>raw</read_mode><!--raw[default]|semi-unified/-->
</source>

 

Regards,Ze Kai

0 Kudos
Highlighted
Champion
Champion

Afaik this is a known limitation - Logs are sent from CMA level only.

0 Kudos
Highlighted
Admin
Admin

Log Exporter does not retrieve the Gaia OS logs.
If you want to export the OS logs, that has to be configured in the OS itself.
Screenshots or exact CLI commands you used would be helpful.
0 Kudos