Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

how to configure external syslog on checkpoint firewall R77.20 and Splat 75.40.

Hi Team,

Please guide, how to configure external syslog on checkpoint firewall R77.20 and Splat 75.40 to send logs on port 514 to external Syslog Server ?

0 Kudos
3 Replies
Highlighted
Admin
Admin

How are these gateways managed precisely?
Are you using an external security management server and if so what version.
For R77.20 in particular, it's important to know what hardware as there are different OS variants which have different steps.

Note that generally, from these versions, there either is no mechanism available to export logs via syslog or the mechanism to do so is lacking.
As those versions are not supported any longer (except on some SMB appliances where R77.20.87 is the latest release available), your best bet is to upgrade to a supported release.
For self-managed SMB appliances in particular, the ability to directly export via syslog is only supported in the 1500 Series running R80.x code and isn't available in models still running R77.20 code.

In regular R80.x gateways, Log Exporter can be used to send logs via syslog.
0 Kudos
Highlighted

All our 77.20 gateway is integrated with Provider-1.

There is any way to configure Syslog in Provider-1 so all the tracker logs will be forwarded to external server.

0 Kudos
Highlighted
Admin
Admin

What version is on your MDM?
For R77.x, there is CPLogToSyslog, but unless you are running a stock GA environment with no hotfixes, it's unlikely these fixes will work.
Unless TAC has something for your precise environment handy, you will need to upgrade as these releases are End of Support.
CPLogToSyslog is here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

For R80.x management, use Log Exporter, which is a more robust and reliable solution than CPLogToSyslog.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
0 Kudos