- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello mates,
A customer needs to send logs to a Syslog Server directly from Security Gateways which are managed by Smart-1 Cloud SMS.
Where has the "Send logs and alerts to these log servers" table gone inside the Cluster object Logs menu?
In OnPrem deployments to add syslog servers to forward logs directly from the gateways you can double-click the Security Cluster object, then click "Logs" in the left menu tree and add a third party syslog server in the "Send logs and alerts to these log servers" table.
I can't seem to find this table anymore in the security cluster object which is managed by Smart-1 Cloud SMS.
Is there any workaround to this or should I use the Log Exporter in the Infinity Portal?
Is there another way to forward Gateway logs to a syslog server in parallel to the S1C which already receives the logs?
Please, also find a screenshot attached with the Log options inside the Cluster object.
Ok, then the it is simple. You configure a cp_log_export on the SMS, and when the log arrives, it will be sent immediately to the external SYSLOG server.
Syntax:
cp_log_export add name <Name> [domain-server {mds | all}] target-server <HostName or IP address of Target Server> target-port <Port on Target Server> protocol {udp | tcp} format {syslog | splunk | cef | leef | generic | json | logrhythm | rsa} [<Optional Arguments>]
Akos
If gateways are managed by Smart-1 Cloud, logs can only be exported from Infinity Portal using Log Exporter (note this requires a specific SKU).
You can configure syslog on the gateway as @AkosBakos suggested, which should send firewall logs (not other blades) as they arrive on the gateway to the configured syslog server.
Hi @L3on
My opinion is that, using cp_log_export is much more easier/safer, but oldschool.
What kind of logs want you to forward? Traffic logs? If yes:
NetFlow Export https://support.checkpoint.com/results/sk/sk102041
You can send logs direcly from the gateway. There are limitations, so start with this chapter.
Q: Cluster object, then click "Logs" in the left menu tree and add a third party syslog server in the "Send logs and alerts to these log servers" table.
or:
Akos
Thanks for the quick response.
I need to send firewall logs to the syslog at the same time they are being sent to the SMS.
Ok, then the it is simple. You configure a cp_log_export on the SMS, and when the log arrives, it will be sent immediately to the external SYSLOG server.
Syntax:
cp_log_export add name <Name> [domain-server {mds | all}] target-server <HostName or IP address of Target Server> target-port <Port on Target Server> protocol {udp | tcp} format {syslog | splunk | cef | leef | generic | json | logrhythm | rsa} [<Optional Arguments>]
Akos
If gateways are managed by Smart-1 Cloud, logs can only be exported from Infinity Portal using Log Exporter (note this requires a specific SKU).
You can configure syslog on the gateway as @AkosBakos suggested, which should send firewall logs (not other blades) as they arrive on the gateway to the configured syslog server.
Thank you for reply!
But with the syslog configuration on the gateway, would the firewall logs still be forwarded to the Smart-1 Cloud SMS as well?
Or would they be missing from the logging in the Logs&Monitor view in the Infinity Portal?
The logs should still appear in Smart-1 Cloud, yes.
The syslog is "in addition to" in this case.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 32 | |
| 18 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY