cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Iron

Log Exporter to Syslog Server

Jump to solution

Hi all,

We're setting up 3rd party network monitoring for our network. The 3rd party has requested that the Check Point logs are sent to their monitoring server to port 10527.  That's fine, we've configured Log Exporter to do that.

I've done a tcpdump on the CP management server and can see packets being sent from it, using ports 40617 and 53660, to the monitoring server's port of 10527. I've looked on the CP logs and the last time packets were accepted was last week (not long after I setup the firewall rule). Nothing has hit since then.

Have I missed anything out? As far as I can see I have done everything needed. Any suggestions would be appreciated!

 

0 Kudos
1 Solution

Accepted Solutions
Highlighted

Re: Log Exporter to Syslog Server

Jump to solution
When the connection is started, it will add a line in the logs for the Syn packet it sees. As long as the connection is running, it will not be restarted until there is a reason to start a new session, ie a change in the configuration of the log export, which requires a restart of the processes.
Regards, Maarten

View solution in original post

0 Kudos
2 Replies
Highlighted

Re: Log Exporter to Syslog Server

Jump to solution
When the connection is started, it will add a line in the logs for the Syn packet it sees. As long as the connection is running, it will not be restarted until there is a reason to start a new session, ie a change in the configuration of the log export, which requires a restart of the processes.
Regards, Maarten

View solution in original post

0 Kudos
Highlighted
Iron

Re: Log Exporter to Syslog Server

Jump to solution

Hi Maarten,

Thanks for clarifying.

0 Kudos