- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I have integrated Checkpoint R80.40 with an SIEM tool via log exporter configuration.
SIEM teams is looking for Geo Location information from these syslogs..is it possible to get this information from syslogs ?
Are you using geo objects in your access policy?
Search for src_country / dst_country in sk144192 to understand the mappings.
Thanks for the reply.. no i am not using geo objects but i was wondering if any location information can be filtered from syslogs ..like in smartconsole logs we can see a location flag against source and destination IPs
I am not SIEM guy by any means, but from what I know, dont believe you can do it that way, though I could ask one of my colleagues, as I know he did something even better for a customer.
I emailed my colleague your question, so will see what he says.
Thanks 🙂
Well, dont thank me yet :-). I did ask, but lets see if I get the answer...if this is something he put lots of work into, I cant guarantee he can share it, but I will let you know either way.
Cheers.
Hey @LostBoY . This is a response I got from my colleague to your initial question:
"You can only get external IP and then the SIEM should have the capability to map the IP to country and city name etc. Usually SIEM tools are equipped with GEOIP databases and lookups. Syslog will include only external IPs"
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY