Hello all.
Is there a way to setup a notification when a Checkpoint gateway device stops logging to it's designated central log server?
I have seen cases where the gateway is operating normally but for one reason or another logs are not being successfully sent to the central log server. It would be great if an alert could be generated when this occurs so the issue can be investigated and addressed asap.
Is there a way this could be done?
Currently I think the only way to determine if a gateway is logging to the central log server is through a manual audit. No one wants to or should be expected to manually audit the log server to determine if the security logs from any of the managed devices are being received or not. Especially problematic in large environments
Thoughts?