- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Sending Check Point logs via LogExporter to Sk...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sending Check Point logs via LogExporter to SkyBox
Hello,
I am curious if anyone has successfully sent Check Point logs to SkyBox via the LogExporter tool. I was able to send the syslogs to the SkyBox server, but apparently SkyBox cannot interpret it correctly due to a date/time format issue.
According to SkyBox, they are expecting the format below from Check Point CMA (Provider-1):
2013-01-06 16:07:55 Local4.Info 10.1.1.1 cma1: 16Sep2012 15:53:54 accept 10.2.2.2 >eth0 rule: 1; rule_uid: {42B0B1D4-73B6-4FEC-97D0-9BBE0AF18742}; service_id: ssh_version_2; src: 192.168.1.1; dst: 10.2.2.2; proto: tcp; product: VPN-1 & FireWall-1; service: 22; s_port: 53753; product_family: Network;
But, this is what SkyBox is receiving from the Provider-1 instead:
Jun 5 04:00:01 XXXXXXXXXX 2019-06-05T07:59:58Z XXXXXXXXXX CheckPoint 9066 - [action:"XXXXXXXXXX"; flags:"XXXXXXXXXX"; ifdir:"XXXXXXXXXX"; ifname:"XXXXXXXXXX"; loguid:"XXXXXXXXXX"; origin:"XXXXXXXXXX"; time:"XXXXXXXXXX"; version:"XXXXXXXXXX"; __policy_id_tag:"product=VPN-1 & FireWall-1[db_tag={XXXXXXXXXX};mgmt=XXXXXXXXXX;date=XXXXXXXXXX;policy_name=XXXXXXXXXX]"; dst:"XXXXXXXXXX"; origin_sic_name:"XXXXXXXXXX,O=XXXXXXXXXX"; product:"XXXXXXXXXX"; proto:"XXXXXXXXXX"; rule:"XXXXXXXXXX"; rule_name:"XXXXXXXXXX"; rule_uid:"{XXXXXXXXXX"; s_port:"XXXXXXXXXX"; service:"XXXXXXXXXX"; src:"XXXXXXXXXX"; ]
Thank you in advance for your help/suggestions.
Thomas
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Thomas, I apologize about the mixed messaging.
Check Point’s Log Exporter is 100% standard output format. If we hadn’t went with the standards, we wouldn’t have been accepted as verified partners of Splunk, Arcsight and AlienVault.
I reached out to Skybox. The reason why Log Exporter is not officially supported by Skybox is because it is technologically different than LEA. So at the moment, in order to use Skybox, LEA must be accepted.
Check Point is working with Skybox and the rest of our technology partners in order to increase adoption of Log Exporter. LEA is still supported in all versions, however we encourage everyone to move to Log Exporter for efficiency, standardized formats, and TLS support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @All,
For informartion, we have tested R80.30 logExporter with 10.1.303 skybox version and it works fine.
Regards.
n.n

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I was told by the SkyBox team that SkyBox expects "structured syslog format".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Thomas, I apologize about the mixed messaging.
Check Point’s Log Exporter is 100% standard output format. If we hadn’t went with the standards, we wouldn’t have been accepted as verified partners of Splunk, Arcsight and AlienVault.
I reached out to Skybox. The reason why Log Exporter is not officially supported by Skybox is because it is technologically different than LEA. So at the moment, in order to use Skybox, LEA must be accepted.
Check Point is working with Skybox and the rest of our technology partners in order to increase adoption of Log Exporter. LEA is still supported in all versions, however we encourage everyone to move to Log Exporter for efficiency, standardized formats, and TLS support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have just open a case to skybox support because LEA opsec doesn't work correctly with huge logs. They recommand us to configure log exporter on our R80.30 MDS.
Our skybox version is 10.1.303.
What do you think about this ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @All,
For informartion, we have tested R80.30 logExporter with 10.1.303 skybox version and it works fine.
Regards.
n.n
