- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Multi-Domain Server Syslog to CP Log Exporter
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multi-Domain Server Syslog to CP Log Exporter
Hi,
I am currently having an issue where the MDS server syslog is not being exported to our syslog server using Check Point log exporter. Check Point log exporter seems to be working well with exporting received firewall syslog messages but MDS is unable to export the syslog messages.Forwarding to management server is enabled on MDS server webUI. Are there any configurations we are missing out?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That being said, here is why you will not get the syslog information from the MDS into any Syslog Forwarder stream:
All syslog forwarders are connected to a specific domain, the MDS itself is not, if it will forward the syslog to a CP domain it will most probably be the Global domain. So when you have a forwarder on the global domain, I really don't know what you will get, all logs for all domains or only these syslogs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Marteen,
We are able to receive and export Check Point logs that are received in the Smart Console. We are however unable to receive and export syslog messages such as SSH login or WebUI login on the MDS sever.I suspect MDS server syslog is unable to send Check Point logs. I am attempting to use Log exporter to export logs in /var/log/messages but I have no clue about the log_file field parameter inside the targetConfiguration.xml.
<source>
<log_files>1</log_files><!-- on-line[default] | read logs from [number] days back (recommended) | specific file name -->
<log_types></log_types><!--all[default]|log|audit/-->
<folder>/var/log</folder><!--$FWDIR/log[default]|specific path-->
<read_mode>raw</read_mode><!--raw[default]|semi-unified/-->
</source>
Regards,Ze Kai
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Afaik this is a known limitation - Logs are sent from CMA level only.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you want to export the OS logs, that has to be configured in the OS itself.
Screenshots or exact CLI commands you used would be helpful.
