- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Checkmate
I have one question related dedicated logs server and the dedicated smart event server
What is the best practice to configure log settings from the gateway send to dedicate logs server and dedicate smart event server?
Example:
1 Security Management VM
1 VM Smartlog Server
1 VM SmartEvent
SmartEvent gets its logs from Log Server, see https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_LoggingAndMonitoring_AdminGu...
still not clear about this link
My question is if we have a separate VM server let say
1VM running as Smart event server and other 1VM functions running as a log server
How do we get logs from the gateway?
GW sends logs to log server. SmartEvent pulls the events from log server to correlate and store them. Using SmartConsole, you connect to SMS to see or save SmartLogs, Events and Reports.
So mean we no need to configure the gateway setting to send logs to smartvent server? send to only log server ok?
and could I know what is the benefit to deploy a dedicated smartvent server?
No. You don't need to configure it on the Gateway.
You would only do this If you wanted the SmartEvent server to be a last resort backup in case the log server was unavailable.
Performance and scalability. Most customers typically start with Mgmt & SmartEvent, sizing determines if they are the same machine or separate.
Dedicated log servers might also be for retention or performance reasons. In a basic deployment the Mgmt also serves as a log server.
One more question:
If we have a SIEM solution and want to export logs to SIEM should we export on both servers and do you have any document best practices to export log servers to SIEM?
Log server machine
and Smarteevent server machine
Log Exporter is used here, see sk122323 and the relevant admin guides to configure the export from the Log server. In recent versions this can be done via SmartConsole.
In order to export all the traffic logs you need to define it on the log server.
If you want it to export correlated events you need to define it for the SmartEvent server as well.
The above looks as expected, you can optionally set the mgmt as a backup log server if you choose.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 9 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY