- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Log exporter and mobile access blade
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log exporter and mobile access blade
Started using the log exporter to send logs to a new SIEM. The only issue so far is that i'm not seeing anything from the mobile access blade sent. i'm getting all other logs. I've even modified this file to only send mobile access, and absolutely nothing arrived at the SIEM.
Version is r81.10
Any ideas would be greatly appreciated.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are correct, it's not considered "Mobile Access". Opened a tac and got it sorted out pretty quick. This config got us to where we wanted to be:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you seeing Mobile Access logs in SmartView?
Note that anything involving a VPN client won’t necessarily show as Mobile Access.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah, we're not looking for their traffic logs. We're more interested in login locations so we can trigger the "geographically improbable" access alarm if jane tries to log on from gig harbor and paris at the same time.
Here's what i currently see in smartview if i filter on blade:mobile access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm wondering if "Mobile Access" is actually the correct product here.
Try checking the raw logs with CPLogFilePrint: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are correct, it's not considered "Mobile Access". Opened a tac and got it sorted out pretty quick. This config got us to where we wanted to be:
