- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I want to integrate my Checkpoint instance to DataDog.. i am wondering what is the best way to do so.. should i just configure a syslog server , forward all Checkpoint logs to that syslog and integrate that syslog server with datadog.
Additionally, i also came across "Log Exporter" feature in Checkpoint but i didnt get it completely. Does log exporter enables integration directly with SIEM tools ? do i need to install any additional plugins on the GWs for it to function.
Hi,
There are many approaches that you can do to achieve this. So far I've used a syslog server to export logs and then ship them to the right platform (e.g. Azure Log Analytics), and in some cases I have used OPSEC integration with some vendors and systems. In essence it boils down to your preference, needs and specifications.
Cheers,
Predrag
As I have said there are multiple ways to do this. What is the most logical way its up to you... When using cp_log_export tool after adding the log export just restart the added export and it will start exporting the logs. Ensure that necessary ports are open (e.g. Azure NSG's or AWS SecurityGroups where the Syslog is located).
cp_log_export add name to_RemoteServer target-server X.X.X.X target-port 514 protocol udp format syslog
cp_log_export restart name to_RemoteServer
After what you do from the syslog its up to you and DataDog agent 🙂
Thanks, i have configured log exporter like this.. however, at the syslog server i can just see the process id and management server hostname displayed but no connection logs.. do i need to enable any thing else vis log exporter commands.
Thanks
Hi,
did you ever solve this - I get exactly the same (R80.40) - my syslog server just receives Time/Log Server/PID - nothing useful!!
Thanks
Graham
Hi,
i have updated my firewall to 80.40 and as i read the log_exporter is integrated. But via ssh i can't set the command cp_log_export because of invalid command .
Can someone help me please ?
Thx.
Sven
did you run cp_log_export from expert mode? This should work.
no unfortunately i didnt get any resolution for this.. i end up exporting logs from individual gateways but it doest not serve the purpose..i guess it does not include any audit logs or deny logs
were you able to fix this ?
On R81 Log exporter basic settings can now be configured within the management object.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY