- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Exporting R80.10 logs to Logstash ( ElasticSearch ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Exporting R80.10 logs to Logstash ( ElasticSearch integration)
Hello,
we are trying to integrate logs from Check Point Management server into Logstash. We are using opensource tool fw1-loggrabber with support of new OPSEC API (SHA-256) supported. Exporting works, however I couldn't find a proper documentation of the fields that can be found in logs. There is not really a true structure of logs, many line have different fields and those fields are not documentated.
Is there a document that show every field that can be exported? I just found an old LEA document, but it is missing a lot of fields. (http://dl3.checkpoint.com/paid/0f/LEA_Fields_2011.pdf?HashKey=1503666450_ebd2eeca265aaca0f531f781169... ).
Writing rules for matching in Logstash is very difficult, without the knowledge what we can expect. We were following Check Point Firewall Logs and Logstash (ELK) Integration - /dev/random
Thank you for any insight how we can do this better.
- Tags:
- logstash
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've added a couple of updated documents on LEA:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've added a couple of updated documents on LEA:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
perfect! I face same issue. will try this, Thanks a lot! sir.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nowadays it might be more useful to use CP log exporter instead
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you! sir. will check our Log Exporter work with ELK stack.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believed with a SMS in R80.20 is possible send logs to logstash through syslog.
