- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Log Exporter - Log Field description
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log Exporter - Log Field description
Hello All,
This is Tim.
I'm using Checkpoint 4600 and Log Exporter to get Syslog from device into my log server.
Actually, It is pretty good well.
but I don't know that when i explore the syslog which comes from checkpoint, I couldn't understand what each fields mean.
https://community.checkpoint.com/t5/Logging-and-Reporting/Log-Exporter-CEF-Field-Mappings/td-p/41060
Above link, there are lots of filed of syslog. but they don't tell us what each fields mean.
So, Where can I get information of syslog field?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A recently added knowledge base article (sk144192) lists the fields, potential values, and it provides a proper description for each field. This link might provide the information that you seek.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A recently added knowledge base article (sk144192) lists the fields, potential values, and it provides a proper description for each field. This link might provide the information that you seek.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some types seem to be wrong in sk144192. For example:
When receiving logs from log exporter, the "action" field is actually a "string", not an "int". The values are "Accept","Drop", etc.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hth,
bob
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, but the fields "severity" and "confidence_level" are sent as integer, not resolved from dictionary. Why is "action" resolved?
It doesn't matter the original type of the field, if the purpose of the table is to help us in use with SIEM, I believe it should report the type that we will receive. Don't you agree?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Bob,
I always comment on SKs that I don't agree with. Sometimes I get answers, most times I don't.
Thank you for also sending your comments!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the feedback!
I will look into it and will update.
