Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BeaconBits
Contributor

Integration with Microsoft Sentinel

Hello everyone,

I'm sending logs to MS Sentinel.

To do this I ran a command on Checkpoint Management Server:

cp_log_export add name <server-name> target-server <server-IP> target-port 514 protocol tcp format cef
cp_log_export restart
cp_log_export status

 

I can see logs are being received in the MS sentinel through the proxy server that is <server-IP>.

But I see huge logs are coming into MS Sentinel and it is increasing our cost in Azure.

The Log Exporter document is telling about field restriction Log Exporter - Check Point Log Export

How can we optimise this?

Real example would be appreciated.

 

Thanks!

B

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

You first have to identify what logs you do not wish to send via Log Exporter.
This is usually based on a specific product, at least as a starting point.

0 Kudos
BeaconBits
Contributor

Thanks @PhoneBoy 

How do I know what Log_Exporter is sending at first place?

On Sentinel I see Kernel logs and some other non-necessary logs that does not require.

From Log_Exporter point of view I would like to see what it is sending... is there any way to see then it would help to restrict what not to send. 

0 Kudos
PhoneBoy
Admin
Admin

If it shows up in your Check Point logs, absent any explicit filtering configuration, it's being sent to Log Exporter.
Further, updates on "Sessions" are being sent again with updated information every 10 minutes (true if the logs involve amount of data sent/received).

This thread might be helpful in terms of configuring a product-specific filter: https://community.checkpoint.com/t5/Management/log-exporter-filterconfiguration/m-p/120214#M26888 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events