Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
maddah87
Contributor
Jump to solution

S1C with separate on premises log server???

Hi,

Just wanted confirm, is it possible to have Smart-1 cloud enterprise gateway management with On premises Log server rather extending smart-1 cloud?

 

0 Kudos
1 Solution

Accepted Solutions
Lesley
MVP Gold
MVP Gold

Getting data to cloud is OK, getting data from the cloud to onprem is expensive! Would find more affordable solution 😉 

But anyway it is not possible:

-------
Please press "Accept as Solution" if my post solved it 🙂

View solution in original post

6 Replies
the_rock
MVP Diamond
MVP Diamond

I dont believe you can do that. What you could do is forward the logs from S1C to onprem, but I dont think you can have separate on prem log server with dedicated S1C. I could be mistaken, so let someone else confirm, for sure.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Lesley
MVP Gold
MVP Gold

Getting data to cloud is OK, getting data from the cloud to onprem is expensive! Would find more affordable solution 😉 

But anyway it is not possible:

-------
Please press "Accept as Solution" if my post solved it 🙂
maddah87
Contributor

Thanks for the insights, the problem occurs when daily log rate increases. Adding log extensions may expensive than the on prem log server.

Thanks all for great inputs

0 Kudos
PhoneBoy
Admin
Admin

We introduced an Aggregated mode to log ingestion in R82.10 and R82/R81.20 via JHF to assist with the log rate.
See: https://community.checkpoint.com/t5/Events/Tech-Tip-log-ingestion-problem-change-log-level-to-reduce... 

0 Kudos
(1)
Lesley
MVP Gold
MVP Gold

You can consider to reduce the logs of high hit rules, or change them from accounting / detailed to normal log. Or disable log at all. You can also split logs into 2 rules, one with logs one without to make sure you don't log stuff that is not needed.

On the firewall you can run this command to see the top 5 hit rules:

cpstat blades

Top Rule Hits
-----------------------
|rule index|rule count|
-----------------------
|Rule 14 | 5147602|
|Rule 19| 1494552|
|Rule 570| 92130|
|Rule 269| 33766|
|Rule 147| 25880|
-----------------------

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Amir_Senn
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

Hi,

Correct me if I'm wrong, but maybe this is unrelated.

Maybe it's an issue to send information from S1C to a log server, but the logs are being sent from the SGW. This might still be supported.

Kind regards, Amir Senn
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events