Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Copper

How do you send CheckPoint log to ELK?

Hello, engineers,How do you send CheckPoint log to ELK?Thank you very much for your support

0 Kudos
6 Replies
Highlighted

Re: How do you send CheckPoint log to ELK?

Hey Wang,

You might want to have a look at the documentation provided by @PhoneBoy  in the link below:

https://community.checkpoint.com/t5/Logging-and-Reporting/Exporting-R80-10-logs-to-Logstash-ElasticS...

I hope this helps.

0 Kudos
Highlighted
Copper

Re: How do you send CheckPoint log to ELK?

Thank you very much
0 Kudos
Highlighted

Re: How do you send CheckPoint log to ELK?

No problem at all, if you could accept it as a solution and give a kudos even it would be much appreciated 🙂

Highlighted
Admin
Admin

Re: How do you send CheckPoint log to ELK?

The problem with this thread is it's still being done with LEA.
Really, you should be using Log Exporter to do this.
I presume ELK can take logs over syslog?
Whether it can parse them is a different story.
Highlighted
Copper

Re: How do you send CheckPoint log to ELK?

Thank you
0 Kudos
Highlighted

Re: How do you send CheckPoint log to ELK?

Log Exporter works like a charm to send logs to ELK, I used syslog in one of our customers.

As PhoneBoy said, true challenge is on the parsing side. I suggest you to look the new SIEM feature from the ELK team, maybe it has some nive out of the box parsers.

____________
https://www.linkedin.com/in/federicomeiners/