- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
Is anyone sending logs to ArcSight and is using the IPS blade?
Im having an issue where these specific logs are not sending the destination address.
This only happens with IPS events, the rest of the blades do send the fields I need.
This is on R80.10 latest JHF smartevent and gateways.
We have same issue.
I opened a SR, but TAC just said to use LEA.
Log Exporter is the preferred solution for exporting to a SIEM going forward. If TAC is telling you otherwise, please escalate the ticket.
In this specific case, it sounds like a bug and ensure a Task is filed with R&D. @Dan_Zada
Hi,
Which reading mode are you using (see SK122323).
If you are using "raw", it might be that you get 2 log fragments, but if you will change it to semi-unified, each time a log fragment will be received to the log server, it will export the full log (all data it had until that point).
You can read more about reading-modes in SK122323.
Thanks!
Dan.
I should do this as part of the SR?
I did open an SR and escalating team just asked for tcpdumps when I see IPS events, to basically confirm 1 of 2 outcomes:
1- ArcSight is doing something and dropping the mapping, which I know it doesnt since raw events are not showing this.
2- Log Exporter on anything below R80.30 doesnt have great support sending/mapping this info easily. Support doesnt really recommend upgrading to R80.30 in critical production environments.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY