Hi guys ,
We have used checkpoint security gateway as a cluster then send fw logs to the Syslog which is called Qradar.
Our products version is R80.40 and then there is a problem we face to , its been more than 5 mounts we did not find anything to deal with our problems.
Which is the problem is we have sent security gateway logs to the SYSLOG server but we have seen the logs like more than a usual one. Like we have seen it one log in checkpoint logs and service , but seen it in SYSLOG server 3 times more.
Why we have seen it like that , is there any case you guys face with like above problem ?
we had face to with the problem to exceed to EPS count in SYSLOG.
Thank you
Best Regards