- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi All,
I do have a question related to the Management Server Logs Exporter feature.
I would like to know if the "Accounting" logging did enable in the Security Policy Layer only, will the total bytes value of the connections will get included in the logs as well when sending out to our SIEM via Logs Exporter?
So that our SIEM side able to get all the information related to the total bytes used of the connections.
Thank you
In short: yes.
as I have not much time please check this discussion, I guess it will help
https://community.checkpoint.com/t5/Management/Management-audit-logs-with-Log-Exporter/td-p/247807
cheers
Vince
You should get bytes for Accounting, Detailed, and Extended logs via Log Exporter.
Records are sent via Log Exporter every 10 minutes until the session is closed.
Yes, they would be. We get those details in our siem from the clients' logs in S1C.
In short: yes.
as I have not much time please check this discussion, I guess it will help
https://community.checkpoint.com/t5/Management/Management-audit-logs-with-Log-Exporter/td-p/247807
cheers
Vince
You should get bytes for Accounting, Detailed, and Extended logs via Log Exporter.
Records are sent via Log Exporter every 10 minutes until the session is closed.
Yes, they would be. We get those details in our siem from the clients' logs in S1C.
Hi @the_rock ,
As for what I know there are Accounting Logging both for Access Policy Layer & Application Control Layer separately.
Mind I ask what are the actual difference between the Accounting Logs among these two different layers? Are they the same during the the logging part or no?
Thank you
From my experience, has the same function.
Hi All,
Really appreciate for your explanation and information provided.
Because as for what I know that the Access Policy Layer and Application Control Layer do have the Accounting Logging separately.
Does the total traffic byte get are the same among both of the layers? Or what are the different between the Accounting Logs for the Access Policy Layer and the Application Control Layer?
Thank you
Accounting and Detailed/Extended log the number of bytes passed through the gateway.
We don't count the bytes twice because they're matched by different rules in different layers.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY