i reboot and it work
But after reboot checkpoint mgmt with cpstop, cpstart , i lost my audit log on SIEM
i export log with command : cp_log_export add name splunk target-server 10.*.*.* target-port 7171 protocol udp format splunk - -apply-now
before reboot it still had audit log and send alert to telegram
how can i check this
cp_log_export show
name: splunk
enabled: true
target-server: 10.*.*.*
target-port: 7171
protocol: udp
format: splunk
read-mode: semi-unified
export-attachment-ids: false
export-link: false
export-attachment-link: false
time-in-milli: false
export-log-position: false
reconnect-interval: Not configured, using default
i show cp_log_exort still running , and traffic log had still there