- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello friends, I hope your help with this: Do you know if there is a way to export traffic logs (firewall, appcontrol, ips, etc) from a logserver to another logserver and that this can be visualized through smartlog / smartviewTracker ..? ?
The purpose is to have the same logs on these two logserver since for SMB type equipment (1200R to be specific), the sending of logs in simultaneous to two logserver is not supported. I have seen that you can send one logserver at a time, and send another logserver as long as the first logserver is unreachable.
Can we have it sent to both at the same time? I will greatly appreciate your comments.
Regards,
Michael Briceño.
Disclaimer: following suggestion is a hack and I am not at all certain that it will work, but:
If your management server is a VM, try cloning it, attach its vNIC to a dedicated physical NIC of the host and connect that NIC to a mirror port on the switch that the logs are passing through.
It'll be actually funny if works.
Or in officially approved way:
Hello Vladimir,
Thank you for your comments. But I've seen that for SMB teams, the log forwarding option is not available either. It is clear to me that it is a limitation of the model or type of device.
I have tried to send logs from the same 1200R device as syslog to this second logserver, but only send configuration logs but no traffic.
Will there be another way to make this possible? Any comment is helpful.
Regards,
Michael Briceño.
Forward logs from the primary logging server to the secondary. You'll have to configure the log forwarding not on the gateway, but on your primary management/log server.
I do not believe that you can circumvent the logging limitations of these gateways without adversely impacting their performance.
Oh oh ok! had misunderstood. I'm worth it and I'll tell you how it went. Thanks.
Which version of management are you running?
Is your secondary logserver a Check Point Log server, too?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY