- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Transfer logs to the ArcSight
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Transfer logs to the ArcSight
How I can transfer log messages to SIEM ArcSight ?
- Labels:
-
Integrations
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You would have to contact HPE for assistance with configuring Arcsight to pull Check Point logs.
However, a quick Google search found this: https://hpe-sec.com/foswiki/bin/view/ArcSightActivate/CheckPointFwConfiguration
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
At a customer site I ran into an Arcsight SIEM integration that broke after upgrading from R77.30 to R80. Turned out the OPSEC library used to compile that version of the Arcsight application did not support the SHA-256 algorithm, which is used by default to sign the CRL in R80 and later. See the following for a workaround involving SHA-1: sk109618: OPSEC SIC connection fails.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
CET (Europe) Timezone Course Scheduled for July 1-2
