- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: LogExporter Filters
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LogExporter Filters
Hi guys!
We were testing filters for the LogExporter tool.
We managed to run some filtering but we have one filter pending, we are trying to filter the sending of firewall status logs, which come from the firewall messages.
We are editing the configuration file, one of the examples we were able to replicate is to send only audit logs but actually we need to disable only the sending of fw messages logs.
In the following way we edit the configuration file to meet the auditing requirement.
log_types>audit</log_types><!--all[default]|log|audit/-->
Can anyone give us some guidance?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That looks like the correct thing to edit (set it to audit instead of all).
If it's not working after restarting Log Exporter, I suggest a TAC case: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello PhoneBoy.
How are you?
Thank you for your reply.
In case we want to filter only the logs of the firewall messages, do you know how we should edit this configuration file?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In your original post, you said "we need to disable only the sending of fw messages logs."
By sending only audit logs, you are filtering out ALL firewall message logs (as none will be sent).
In this response, you said "we want to filter only the logs of the firewall messages" which is a bit different.
What are your exact requirement(s) here?
Be as specific as possible and include version/JHF of your management.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello PhoneBoy.
Previously we had implemented the auditlog filter successfully.
Actually we need to see all the firewall logs, only excluding the fw messages, but we could not achieve it.
The management version is R81.20 and the JHF is take 10.
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't understand what "fw messages" you are referring to.
Can you provide specific examples, preferably with a full log card (with sensitive details redacted)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy.
The logs we refer to would be the following based on the following SK: sk144192
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So you do NOT want logs that have something in this field?
Maybe something like the following in your <filters> stanza of $EXPORTERDIR/targets/<Name of Log Exporter Configuration>/conf/FilterConfiguration.xml:
<field name="fw_messages" operator="and">
<value operation="eq"></value> </field>
Otherwise, I suggest contacting the TAC: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As mentioned in sk122323, filtering works only for Action / Blade / Origin fields. Not sure if it is possible to filter out logs with respect to log messages.
