Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wang
Collaborator

How do you send CheckPoint log to ELK?

Hello, engineers,How do you send CheckPoint log to ELK?Thank you very much for your support

0 Kudos
6 Replies
Nick_Doropoulos
Advisor

Hey Wang,

You might want to have a look at the documentation provided by @PhoneBoy  in the link below:

https://community.checkpoint.com/t5/Logging-and-Reporting/Exporting-R80-10-logs-to-Logstash-ElasticS...

I hope this helps.

0 Kudos
Wang
Collaborator

Thank you very much
0 Kudos
Nick_Doropoulos
Advisor

No problem at all, if you could accept it as a solution and give a kudos even it would be much appreciated 🙂

PhoneBoy
Admin
Admin

The problem with this thread is it's still being done with LEA.
Really, you should be using Log Exporter to do this.
I presume ELK can take logs over syslog?
Whether it can parse them is a different story.
Wang
Collaborator

Thank you
0 Kudos
FedericoMeiners
Advisor

Log Exporter works like a charm to send logs to ELK, I used syslog in one of our customers.

As PhoneBoy said, true challenge is on the parsing side. I suggest you to look the new SIEM feature from the ELK team, maybe it has some nive out of the box parsers.

____________
https://www.linkedin.com/in/federicomeiners/

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events