Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sagar_Manandhar
Advisor

Send specific log to SEIM

Hi,

Is there the way for management server to send only specific logs ( like critical ips log only,high bandwidth application and url log) to SIEM ?

We are trying different SEIM product for POC (proof of concept) but due to huge log the device is not able to process the log as for POC they are using the low end devices.

Regards,

Sagar Manandhar

 

1 Reply
Alejandro_Mont1
Collaborator

Are you using LEA or Log Exporter? If using LEA I believe logs are pulled, not sent from the Check Point device so there would be nothing on the management server to change. If using Log Exporter sk122323 under Advanced Deployment there is a Filter Parameters paragraph that details how to exclude firewall blade logs.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events