Hi Team,
We are facing issues in getting audit logs from Checkpoint R80.10. We have MicroFocus ArcSight in our environment.
We are receiving the traffic logs without any issues and the same is getting parsed properly. But the audit logs which we receive in "SmartConsole" is parsed as "Log" and nothing much is captured in raw event. At the same time from other firewall which are on R80.20 we are receiving "Log in", " Log Out", "Modify Rule" etc events and username and other details are captured.
The targetconfiguration.xml settings file is set as "all"
<log_types></log_types><!--all[default]|log|audit/-->
Also, the output of cp_log_export show command on the management server is:
name: ArcSightLog
enabled: true
target-server: Agent Server IP
target-port: 514
protocol: udp
format: cef
read-mode: semi-unified
In one of the thread I saw that the domain-server argument needs to be provided while configuring the log export destination. Can someone please check the above config and tell if it was added or not?
Please help in rectifying the issue. What configuration we need to use in order to receive audit logs from R80.10 using Log exporter solution.
TIA
Regards,
Mitesh Agrawal