- CheckMates
- :
- Products
- :
- General Topics
- :
- How do you send CheckPoint log to ELK?
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do you send CheckPoint log to ELK?
Hello, engineers,How do you send CheckPoint log to ELK?Thank you very much for your support
6 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Wang,
You might want to have a look at the documentation provided by @PhoneBoy in the link below:
I hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No problem at all, if you could accept it as a solution and give a kudos even it would be much appreciated 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem with this thread is it's still being done with LEA.
Really, you should be using Log Exporter to do this.
I presume ELK can take logs over syslog?
Whether it can parse them is a different story.
Really, you should be using Log Exporter to do this.
I presume ELK can take logs over syslog?
Whether it can parse them is a different story.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log Exporter works like a charm to send logs to ELK, I used syslog in one of our customers.
As PhoneBoy said, true challenge is on the parsing side. I suggest you to look the new SIEM feature from the ELK team, maybe it has some nive out of the box parsers.
____________
https://www.linkedin.com/in/federicomeiners/
https://www.linkedin.com/in/federicomeiners/
