- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I just upgraded from R80.20 -> R81.10 and created some custom parsing in our Logrhythm SIEM for Checkpoint Syslog Exporter. However, we get little to no value from specific blades and I would like to exclude those from sending to our SIEM. Specifically I would like to exclude HTTPS Inspection. I see a lot of options for filtering in by blade but not filtering out a blade. Any help here?
Thanks, that worked for me. Although I had to adjust to focus on Product since a lot of the other blades have inspection actions in the values. I used the below filter. This works since the blade name is mapped to product in Logrhythm.
<filters>
<filterGroup operator="and">
<field name="product" operator="or">
<value operation="neq">https inspection</value>
</field>
</filterGroup>
</filters>
| Configuration Method | Description |
|
Using the |
This command configure filtering for Action / Blade / Origin fields only. The syntax is:
In addition, it is possible to use predefined families for "
|
I have the same case with TS, follow the filter as per sk but the SIEM become not receiving any logs and I saw message "Logs Formatter :: Process Log Skipped".
Any idea?
I would suggest to contact TAC to get this resolved !
I saw this but there is only a filter in option not a filter out option. So do I need to specify all blades I need to filter in? I also don't see HTTPS inspection blade in any of the families. Would that be excluded if I select just Access and TP?
Have you tried playing with FilterConfiguration.xml file? sk122323
Fields can be found here sk144192
You could try excluding https_inspection_action or specific HTTPS rule UID (apparently name is not supported)
<field name="https_inspection_action" operator="or">
<value operation="neq">Inspect</value>
<value operation="neq">Bypass</value>
<value operation="neq">Error</value>
</field>
Thanks, that worked for me. Although I had to adjust to focus on Product since a lot of the other blades have inspection actions in the values. I used the below filter. This works since the blade name is mapped to product in Logrhythm.
<filters>
<filterGroup operator="and">
<field name="product" operator="or">
<value operation="neq">https inspection</value>
</field>
</filterGroup>
</filters>
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY