- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Log exporter exclude certain rules / geo traff...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log exporter exclude certain rules / geo traffic
Hello,
I was wondering if there's a way to exclude certain rules from being passed on to QRADAR syslog via Log Exporter.
Since we are using the security rule base policy in order to manage Geo Blocking, this traffic is considered as access traffic.
I would like to exclude this traffic from being passed on to syslog.
This is the config we are using atm:
format leef filter-blade-in "Access,TP" read-mode semi-unified
Labels
- Labels:
-
Logging
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe you can filter based on rule UID.
Meaning send logs for rules that are not one of those rule UIDs.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
