- Products
- Learn
- Local User Groups
- Partners
-
More
It's Here!
CPX 360 2021 Content
Check Point Harmony
Highest Level of Security for Remote Users
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
Advanced Protection for
Small and Medium Business
Secure Endpoints from
the Sunburst Attack
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi!
I have tried to find a way to set a specific syslog Facility code for my auditlogs with the the cp_log_export function, but I cannot find that feature. It seems to use the default Facility code 0 by default.
Does anyone know if this is possible or planned for any coming releases?
Regards
Mattias Jansson
I think this was/is possible with sk115392: How to export Check Point logs to a Syslog server using CPLogToSyslog :
The following table shows the values and meanings of Facility Indicators that are used in the event_format
section of the policy file
(refer to section "(5-E) Configuration instructions - Rulebase").
The Facility Indicators are used to specify what type of program is logging the message.
This lets the administrator specify that messages from different facilities should be handled differently
(refer to https://linux.die.net/man/5/syslog.conf).
Interesting.
That seems to be the older tool that was supported until R80.10.
We are on R80.20.
So I hope that the possibility to set the facility indicator will be implemented in coming relases of the new feature.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY