- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We implemented CheckPoint and ArcSight integration (via OPSEC server, clear connection).
What logs will be sent to ArcSight? For example, we try to log in via Endpoint Security VPN. In CheckPoint logs we see log in and log out events, but in ArcSight we see only log out events.
Why?
Please specify the version of Check Point management server that the ArcSight is retrieving data from.
Additionally, please indicate if you are looking at the parsed or raw data on ArcSight and if any of the fields in the messages on ArcSight contain ***Confidential*** in them.
CheckPoint management server version: R77.30.03.
We had ***Confidential*** fields, but we apply recommendations for clear connection between CP and ArcSight, which help to show these fields.
Did you follow this Arcsight LEA client shows the username field as "Confidential" sk to display user names?
No, we used sk101570, item 3.
Hi Olga
Did the work on item 3 fixed the issue for you, we have the same issue, where we use ArcSight clear connection (without OPSEC object defined), on SmartEvent R80.10
Following parameter shows as 1 after the given chage, but still I get the ***Confidential***, anything else did you do or just changing the parameters
echo $LEA_CLEAR_DISABLE_CONFIDENTIALITY
1
Hi,
We are in a planning phase to implement smart-1 with SIEM, can you pls provide with implementation steps or procedure on how to do it?
Actually we are running an EA version of logexporter. This is a hotfix so you can send the logs already in CEF format to Arcsight. this wil output all logging you can configure yourself what logging you want to receive.
Don't know when the GA is available but think it will be soon.
best regards,
Maarten Lutterman
I believe this is part of the LogOut project (discussed here previously).
That said, if you want in on the Early Availability testing, please send me a Private Message.
Dameon,
Thanks for your proposal.
I think we will wait for this logexporter to be tested by the CheckPoint team and officially released.
Hi, the Log Exporter tool is now official GA and more details can be found in sk122323
Hi, is Log Exporter the same thing as LogOut?
Yes, LogOut was the Internal name of the project that produced the Log Exporter utility.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY