- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
In order to centralize gateway system logs, I'm using the "set syslog cplogs on"-option to forward the local /var/log/messages from hundreds of gateways to our Check Point logging server.
Technically, this should allow us to do reporting, post-processing and filtering on these system logs.
It appears though not all syslogs are parsed correctly, resulting in valuable data falling back to the "default_device_message"-field.
This particular field is not usable in reports, hence no post-processing is possible.
Attached an example of an extract of 3 gateways.
I opened a ticket with Check Point TAC, though after months of discussing with R&D, they claimed it is "normal" a Check Point Log Server does not understand system logs sent by Check Point Gateways and recommend me to create a parser.
I was wondering if anyone in the community has created parsers like these in the past (sk55020) and if you would be so kind to share these.
Many thanks in advance!
Most of what comes from local syslog doesn't necessarily translate into a logging system designed for network traffic.
We do not do this by default, but we provide the ability to create a parser to do it to your specification.
I haven't seen too many people posting syslog parsers to the community.
/var/log/messages contains tons of useful firewall related messages.
Most vendors have some sort of central logging for these type of system messages in order to better manage these in large scale environments, which is what I'm trying to accomplish with Check Point as well.
I don't disagree.
However, the product is operating as designed in this situation.
You can discuss your precise requirements with your local Check Point office so an RFE can be filed.
It's also possible Check Point Professional Services could create an appropriate parser to your specifications (at cost).
RFE 5KH6K4Jmn was launched somewhere in July and was forwarded to our local SE's.
Perhaps I'll take a shot at it when things calm down during the winter break, though Check Point should be paying me then to optimize their product 😉
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY