- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi, tell me, is it possible to configure syslog so that administration data is also transmitted to SIEM (actions performed by administrators on the management server, events related to changing system objects?
Log Exporter - Check Point Log Export will be the tool for your need. You can forward audit logs only .
Yes, I studied this sk, only security and audit logs are sent, it turns out that they do not contain administration data and cannot be sent to siem in any way?
@Arturxr please explain "administration data", maybe with an example which information do you need to send to the SIEM.
If you change something in the rulebase or change objects, these changes are collected in the audit log.
In SIEM, it is necessary to transfer information on changing objects (rules, hosts, subnets, etc.)
This information comes through OPSEC, but can it be configured through the Log Exporter?
@Arturxr as I wrote in my post, this information"changing objects (rules, hosts, subnets, etc." is logged in the audit logs of your SMS and it's possible to send them to SIEM . Have a look at the audit log view in Smartconsole, every information shown there can be send to SIEM. There is no need for the use of the OPSEC interface, LogExporter does this.
I understand correctly? is it set up here?
Yes, that's correct. If you want to send audit logs only you have to do advanced configuration and change the configuration xml file. Change <log_types> all </log_types> to <log_types> audit </log_types>.
Thanks, where can I find this xml file?
Everything you need is found here, please read this.
Log Exporter - Check Point Log Export
The Log Exporter configuration for the target server is saved in:
$EXPORTERDIR/targets/<Name of Log Exporter Configuration>/targetConfiguration.xml
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY