Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
keamas
Explorer
Explorer

Send logs from Infinity Portal to a SIEM Solution

Hi is there any way to send Logs from the Infinty Portal to a SIEM Solution Like Azure Sentinel.

I would like to export CHECK POINT CloudGuard WAF Logs to Azure Sentinel automatically.

Is there any solution ?

 

3 Replies
the_rock
MVP Diamond
MVP Diamond

Yes, there is. See if below helps you. If not, I can ask one of my colleagues, he is Linux AND Siem GENIUS, everyone says that about him 🙂

Let me know.

Andy

https://community.checkpoint.com/t5/Management/Log-exporter-amp-Splunk-TLS/m-p/126164#M27609

https://community.checkpoint.com/t5/Management/Log-exporter-TLS-config-with-QRadar/m-p/115020

https://community.checkpoint.com/t5/Infinity-Portal/Logs-from-Infinity-Portal-to-Splunk/m-p/193420#M...

 

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
genisis__
MVP Silver
MVP Silver

If I remember correctly - you will need to get the collector to generate a certificate so you can then utilise a TLS connecting inbound to the collector, and of course ensure you have the the export licenses (not expensive).

the_rock
MVP Diamond
MVP Diamond

That sounds right. I will confirm with my colleague.

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events