- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- LEA Fields
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LEA Fields
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a new version of this for R80.10?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as I know, not really, since the LEA format didn't change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are a number of new fields logged with R80.10, not to mention a significant increase in the amount of storage space used. Some sort of reference material would be very useful.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What sort of reference material are you looking for? We don't have a complete list of the raw log fields that we can give you today, but as I understand it, this is part of the Log Exporter project. If you are using the LEA API today, its worth your while to have a look at Log Exporter (sk122323). Regarding performance and reducing the size of the logs sent to your syslog server also have a look at the Log Exporter guide discussion.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's more that I am working the other way around. I try to make as much sense as I can from syslog details I get from other sources and translate them to the equivalent fields in Check Point.
iptables output was relative easy. Now I try to make sense out of email syslog output.
Some years ago I wrote a parser addon for logwatch based on How to Parse the Barracuda Email Security Gateway Syslog as shown on Logwatch modules and now I would like to make some sense out of it and push it into Check Point logs so I have a more complete overview of the traffic in my lab.
Apart from the manual a lot can be reverse engineered by just looking around in the GUI. For example no one documents the various values that are valid in the Action field. But that list is easy to see if you open SmartConsole.
