- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Fields dstination ip, ports missing in raw logs se...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fields dstination ip, ports missing in raw logs sent to QRadar
Hi,
I am using Log Exporter (Leef) format for QRadar.
However, I cannot see complete logs, especially in IPS "Exploits" logs. I can only see the source IP, but not the destination IP, destination port, or source port in the logs in my QRadar.
Those fields are needed for the automation we have in-place which worked well with opsec/lea.
May I get the steps to get complete IPS logs. I am using version R81.
Regards,
Sumit
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Solved.
In case if anyone is interested, set log type as semi-unified in expert mode, as command below
cp_log_export set name <name> read-mode semi-unified
command to view log exporters:
cp_log_export show
If log exporter is created using SmartConsole UI,
1. In Objects > Servers > Log Exporter/SIEM, select the object.
2. Right click on object and select Edit.
3. In Left Pane, select Data Manipulation.
4. Check "Aggregate log updates before export".
5. Publish and Install Policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Possible this thread may be helpful: https://community.checkpoint.com/t5/Management/Log-Exporter-LEEF-Field-Mappings/td-p/48905
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Solved.
In case if anyone is interested, set log type as semi-unified in expert mode, as command below
cp_log_export set name <name> read-mode semi-unified
command to view log exporters:
cp_log_export show
If log exporter is created using SmartConsole UI,
1. In Objects > Servers > Log Exporter/SIEM, select the object.
2. Right click on object and select Edit.
3. In Left Pane, select Data Manipulation.
4. Check "Aggregate log updates before export".
5. Publish and Install Policy.
