Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
erann
Contributor

Log exporter exclude certain rules / geo traffic

Hello,

I was wondering if there's a way to exclude certain rules from being passed on to QRADAR syslog via Log Exporter.

Since we are using the security rule base policy in order to manage Geo Blocking, this traffic is considered as access traffic.

I would like to exclude this traffic from being passed on to syslog.
This is the config we are using atm:

format leef filter-blade-in "Access,TP" read-mode semi-unified

111.png222.png

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I believe you can filter based on rule UID. 
Meaning send logs for rules that are not one of those rule UIDs.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events