Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
intaq
Explorer

FilterConfiguration.xml | Log Filtering is not working after upgrade

Hello !

We had configured in the FilterConfiguration.xml file a series of filters to not send traffic events in order not to saturate the SIEM, commenting some lines #. This worked for a while, recently the SMS was updated and this stopped working. The file was not altered, it remains the same as before the update

I have tried restarting with cp_log_export restart and installed DB again in case this could affect but it continues to send traffic logs. The file has not been modified after these tests either.

The version is R81.10 JHF 139

Any ideas or something similar that may have occurred to you? 

Thanks!

0 Kudos
5 Replies
Alex-
Leader Leader
Leader

We have a similar issue with TLS certificates after each jumbo.

 

Restarting the Log Exporter isn't enough, we need to actually delete the instance and recreate it, then everything works again.

0 Kudos
intaq
Explorer

I'm sorry but what do you mean by instance?

0 Kudos
Alex-
Leader Leader
Leader

Your Log Exporter instance.

cp_log_export show to list them, then cp_log_export delete name <NAME> --apply-now, then recreate it with the same parameters.

0 Kudos
intaq
Explorer

Hello!

I have deleted the instance, recreated it and applied the filter, then restarted log exporter but it is still sending logs to SIEM.

 

0 Kudos
PhoneBoy
Admin
Admin

Your best bet is to consult with TAC: https://help.checkpoint.com 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events