- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I just need a sanity check here. I have a customer with multiple VSs running on some 21ks. For reasons too lengthy to go into on this thread they are moving all VSs to physical clusters. I moved the first VS to a 6800 cluster last weekend.
The customer has QRadar setup to the customer's CMA with an OPSEC/Lea connection. They are telling me they are not seeing logs from the new cluster, but still see all of the old logs as they would expect. All logs are visible in the log server including the new hardware cluster.
I am fairly certain on this, but this customer is making me doubt myself. If you have an OPSEC/Lea connection to a log server, there is no way to filter which logs are sent, right? Or which FW logs are sent. It has to be something on the QRadar side that is filtering I would think.
Am I mistaking here? Or is there something that I'm missing which is obvious?
Thanks,
Paul
Paul,
Hope you are doing fine, best way to prove this is to make a packet capture via tcpdump on your management server filtering by the QRadar sensor and the LEA port used.
By the way, I strongly recommend you to use Log Exporter from Check Point if possible. I've used it a couple of times and it works really well with QRadar.
Regards,
Paul,
Hope you are doing fine, best way to prove this is to make a packet capture via tcpdump on your management server filtering by the QRadar sensor and the LEA port used.
By the way, I strongly recommend you to use Log Exporter from Check Point if possible. I've used it a couple of times and it works really well with QRadar.
Regards,
Thanks to those that have replied. We are going to use Log Exporter. Not sure why QR is not seeing the new physical cluster logs, but at this point it doesn't matter. Log Exporter is a much better solution.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY