- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
How can the mappings in cef be customized according to my requirement? I tried changes in $EXPORTDIR/conf/CefFieldsMapping.xml.
Also I tried changing the target fieldmapping.But the changes do not reflect even after I restart cp_log_export.
What can be the solution to the problem
I would suggest asking TAC !
Is there no provision for customization of mapping than at user level?
Is it only possible to map the logs after arriving at third party application?
For eg: I was trying to rename the field rt as log_ts; and have need to customize some other fields too.
I tried changes in field mapping within targets' field mapping. Also I tried changes at conf cef field mappings but to no avail.
@Dan_Zada any comment here?
Any reply here ?? I am out on a limb here.
It is not that urgent. Its just for educational purpose and interest in the Checkpoint. I can wait, but eager to know why it is not working is all. 😄
Hi @sanchez
My name is Shay and I will try to help you with this case.
A bit information about Log Exporter files:
Under log_exporter main directory ($EXPORTERDIR) you will find conf dir where all configuration files exist.
This files are the default files and should not being changed at all.
The reason is because these files are copied to every new log exporter instance you create.
Once a new log exporter instance is created, a new dir for this exporter is created under $EXPORTERDIR/targets/<exporter_name>.
For each exporter instance, you can find conf directory where all configuration files are copied to (the default files).
Any change should be done on these files (the relevant files) in this specific scope.
Now to your issue 🙂
You want to change the mapping of your exporter in order to add 3 more fields.
Since you are using CEF format, go to your exporter's conf directory ($EXPORTERDIR/targets/<exporter_name>/conf) and look for file named CefFieldsMapping.xml.
Backup this file before any changes.
Modify this file by adding the new 3 fields (make sure to add them under <fields> tag):
<field><origName>src</origName><dstName>cef_src</dstName></field>
<field><origName>rt</origName><dstName>log_ts</dstName></field>
<field><origName>dst</origName><dstName>cef_dst</dstName></field>
I'm not sure about rt since rt is already dstName of time field. in case you need to map it, you should do this using time field (an example can be seen on the file itself).
After these changes, you need to restart the exporter in order to reload this configuration by running cp_log_export restart name <exporter_name>
Please let me know if you need any additional help.
Regards,
Shay
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY