Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sangeeth_N
Contributor

Document related to OPSEC configuration

I am in search for a document related to OPSEC configuration in checkpoint to integrate with 3rd party SIEM tools. Kindly share documents if any.

12 Replies
Kosin_Usuwanthi
Collaborator

Maybe you can search from 3rd SIEM that you need to integrate with CheckPoint.

Like this.

IBM Knowledge Center 

Mark_Mitchell
Advisor

Hi Sangeeth,

Are you after anything in particular? As the options you select on the OPSEC configuration may differ per product.

Or are you after a quick how to setup an OPSEC configuration?

As Kosin Usuwanthim‌ has advised the 3rd party should have a guide on how to integrate their product with Check Point.

Regards

Mark

0 Kudos
Sangeeth_N
Contributor

Hi Mark

Yes, we are using ArcSight. 

But the actual issue that we are facing is that "User" field is shown as "Confidential" in logs (Clear connection is configured).

I also gone through sk101570 (3rd Scenario) which is related to our issue. I hope by following the given procedure will solve this issue. Kindly suggest...

Reference : sk101570 

Some fields in logs on 3rd party LEA OPSEC client show "*** Confidential ***" 

Mark_Mitchell
Advisor

Hi Sangeeth, 

Within your OPSEC configuration do you have the LEA configuration settings set to "Hide all confidential log fields"?  This will cause what you are seeing. 

if you can post your OPSEC configuration we can take a look and advise as necessary. 

Regards

Mark

0 Kudos
Sangeeth_N
Contributor

Hi Mark

As stated in earlier comment , the connection type configured is "clear" in ArcSight. I believe that we need not to create an OPSEC application for clear connection.

Regards

Sangeeth

0 Kudos
DeletedUser
Not applicable

Sounds like you're on the right track as far as the LEA options. Let us know how it works out for you.

  • change to sslca as Mark Mitchell shows
  • set the variable LEA_CLEAR_DISABLE_CONFIDENTIALITY as shown in sk101570
Sangeeth_N
Contributor

Hi Bob

I had performed the same :

  • set the variable LEA_CLEAR_DISABLE_CONFIDENTIALITY as shown in sk101570

But the issue is still persisting. "Target User Name " filed in logs received in ArcSight  is still showing as ***confidential ***.

More over the Management Server is running on GAIA Windows OS R77.30.

Dameon Welch-Abernathy‌  Kindly suggest.

0 Kudos
PhoneBoy
Admin
Admin

Danny
Champion Champion
Champion

PhoneBoy
Admin
Admin

Maybe use Log Exporter instead?

Log Exporter guide

0 Kudos
shubhama
Explorer

Log Exporter is used only in R80.* version and not in R77 or below version . 

Please correct me if i am wrong . 

0 Kudos
PhoneBoy
Admin
Admin

You can get Log Exporter for R77.30, but R77.30 and earlier releases are End of Support.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events