- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello community, I have an environment where the export logs in Smart Event are configured for a server in Syslog format.
However, the SIEM team informed me that the collection server is receiving 2 formats, CEF and Syslog. The CEF event is sending the same information as the other event that is in syslog format, but with a messed up header, whereas the correct information should be in each column within the SIEM tool.
I would like to understand why the collection server is receiving in CEF format if the export is configured to be in Syslog format.
The SIEM team performed a traffic capture and is only receiving traffic from Smart Event.
I consulted management and it is also exporting to the same SIEM server and in Syslog format. Does anyone have any idea why this CEF log is being sent? Is this normal behavior?
Can you send output of cp_log_export show?
Also, check out below file to make sure there is nothing unusual there.
From my lab, but you get an idea.
Andy
[Expert@CP-MANAGEMENT:0]# pwd
/opt/CPrt-R82/log_exporter/targets/test-log
[Expert@CP-MANAGEMENT:0]# ls
CPMICache fieldsMapping.xml log_indexer_custom_settings.conf
conf log targetConfiguration.xml
data log_exporter tmp
[Expert@CP-MANAGEMENT:0]# more targetConfiguration.xml
I meant below lines specifically.
Andy
<format type="splunk"> <!--syslog | cef | rsa | leef | generic | splunk | this parameter may differ from the type of destination, for example, destination type = files/format type = CEF -->
I got the following feedback. I see that there is another configuration in the CEF format within Smart Event. However, the only server that is configured is this LogExporter_Test_1.
That would most likely explain the issue.
Can you delete the first entry and try?
Andy
I will delete it and validate it with the SIEM team. I will be back soon to tell you the result. In the meantime, I appreciate your support.
Im positive that will work.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY