cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

Send specific log to SEIM

Hi,

Is there the way for management server to send only specific logs ( like critical ips log only,high bandwidth application and url log) to SIEM ?

We are trying different SEIM product for POC (proof of concept) but due to huge log the device is not able to process the log as for POC they are using the low end devices.

Regards,

Sagar Manandhar

 

1 Reply

Re: Send specific log to SEIM

Are you using LEA or Log Exporter? If using LEA I believe logs are pulled, not sent from the Check Point device so there would be nothing on the management server to change. If using Log Exporter sk122323 under Advanced Deployment there is a Filter Parameters paragraph that details how to exclude firewall blade logs.