Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
furi
Explorer

Checkpoint sent more logs than usual

Hi guys , 

 

We have used checkpoint security gateway as a cluster then send fw logs to the Syslog which is called Qradar.

 Our products version is R80.40 and then there is a problem we face to , its been more than 5 mounts we did not find anything to deal with our problems.

 

Which is the problem is we have sent security gateway logs to the SYSLOG server but we have seen the logs like more than a usual one. Like we have seen it one log in checkpoint logs and service , but seen it in SYSLOG server 3 times more. 

 

Why we have seen it like that , is there any case you guys face with like above problem ? 

 

we had face to  with the problem to exceed to EPS count in SYSLOG. 

 

Thank you 

 

Best Regards

0 Kudos
8 Replies
the_rock
Champion
Champion

Are you saying you see specific log on CP say once, but then see that same log multiple times on Qradar? If so, can you confirm when this started happening, any recent changes on CP side at all?

0 Kudos
furi
Explorer

yeah , exactly what ı want to say  , nothing change on CP actually . there is a continous issue that we face to since have installed security gateway.

0 Kudos
Timothy_Hall
Champion
Champion

This is almost certainly due to Session Logging and/or Log Suppression.  Session Logging can be disabled in the Advanced properties of the Track field of your rules in the SmartConsole, while Log Suppression can be disabled by changing a kernel value on the gateway.

@PhoneBoy can I talk yet about the clarifications that will be coming soon on this in a very public forum?  Second question about it this week...

New 2021 IPS/AV/ABOT Immersion Self-Guided Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
furi
Explorer

hey, 

Thanks your quick respond, ı will share pics about the issue, 

There are differences between them about the log count , but there are also same based on source IP address , destination IP address, the time log passes through log source and then We could see different log count between them, 

 

 fw.PNGQradar-LOG.PNG

0 Kudos
furi
Explorer

as a add to previous reply , also checked session logging field into track field of rules , there is no checked option , just tick per connection not per session. 

0 Kudos
PhoneBoy
Admin
Admin

Not familiar with exactly what is coming regarding this.
Let me know what it is out of band, I'll check.

0 Kudos
Chris_Atkinson
Employee
Employee

Please check if sk171643 is relevant for you.

0 Kudos
the_rock
Champion
Champion

I had exact same issue with one customer using https inspection (shows way more logs for my taste than whats expected), but TAC referenced that sk and said its totally normal. I was never sold on that statement, to be honest, but customer did not want to bother, so we just left it as is.

0 Kudos