- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi guys ,
We have used checkpoint security gateway as a cluster then send fw logs to the Syslog which is called Qradar.
Our products version is R80.40 and then there is a problem we face to , its been more than 5 mounts we did not find anything to deal with our problems.
Which is the problem is we have sent security gateway logs to the SYSLOG server but we have seen the logs like more than a usual one. Like we have seen it one log in checkpoint logs and service , but seen it in SYSLOG server 3 times more.
Why we have seen it like that , is there any case you guys face with like above problem ?
we had face to with the problem to exceed to EPS count in SYSLOG.
Thank you
Best Regards
Are you saying you see specific log on CP say once, but then see that same log multiple times on Qradar? If so, can you confirm when this started happening, any recent changes on CP side at all?
yeah , exactly what ı want to say , nothing change on CP actually . there is a continous issue that we face to since have installed security gateway.
This is almost certainly due to Session Logging and/or Log Suppression. Session Logging can be disabled in the Advanced properties of the Track field of your rules in the SmartConsole, while Log Suppression can be disabled by changing a kernel value on the gateway.
@PhoneBoy can I talk yet about the clarifications that will be coming soon on this in a very public forum? Second question about it this week...
hey,
Thanks your quick respond, ı will share pics about the issue,
There are differences between them about the log count , but there are also same based on source IP address , destination IP address, the time log passes through log source and then We could see different log count between them,
as a add to previous reply , also checked session logging field into track field of rules , there is no checked option , just tick per connection not per session.
Not familiar with exactly what is coming regarding this.
Let me know what it is out of band, I'll check.
Please check if sk171643 is relevant for you.
I had exact same issue with one customer using https inspection (shows way more logs for my taste than whats expected), but TAC referenced that sk and said its totally normal. I was never sold on that statement, to be honest, but customer did not want to bother, so we just left it as is.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY