- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello All,
This is Tim.
I'm using Checkpoint 4600 and Log Exporter to get Syslog from device into my log server.
Actually, It is pretty good well.
but I don't know that when i explore the syslog which comes from checkpoint, I couldn't understand what each fields mean.
https://community.checkpoint.com/t5/Logging-and-Reporting/Log-Exporter-CEF-Field-Mappings/td-p/41060
Above link, there are lots of filed of syslog. but they don't tell us what each fields mean.
So, Where can I get information of syslog field?
A recently added knowledge base article (sk144192) lists the fields, potential values, and it provides a proper description for each field. This link might provide the information that you seek.
A recently added knowledge base article (sk144192) lists the fields, potential values, and it provides a proper description for each field. This link might provide the information that you seek.
Some types seem to be wrong in sk144192. For example:
When receiving logs from log exporter, the "action" field is actually a "string", not an "int". The values are "Accept","Drop", etc.
Ok, but the fields "severity" and "confidence_level" are sent as integer, not resolved from dictionary. Why is "action" resolved?
It doesn't matter the original type of the field, if the purpose of the table is to help us in use with SIEM, I believe it should report the type that we will receive. Don't you agree?
Bob,
I always comment on SKs that I don't agree with. Sometimes I get answers, most times I don't.
Thank you for also sending your comments!
Thanks for the feedback!
I will look into it and will update.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 12 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY