- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- What is the best practices for export logs ?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the best practices for export logs ?
Hello Mates!
Is there any documentation or best practice for exporting logs from SmartEvent/Log Server to an external server?
How do you recommend doing it?
Scripts via SSH? Export option via SmartConsole? Is there any other way? Any native integration with a backup solution?
Thank you all!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?
Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112
Best Practice:
sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server
Refer also:
sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @Bernardes
We always use below for customers and works well.
sk122323: Log Exporter - Check Point Log Export
You can use that to send wherever you like...mostly, I know people use SIEM solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?
Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112
Best Practice:
sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server
Refer also:
sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Chris_Atkinson , thank you very much for your answer!
I need to do this just to keep the logs from a specific customer safe out of the SmartEvent /Log Server VM and if needed in the future, be able to reread them in SmartConsole.
I have read some of these SKs like:
sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers
But the others that you sent I didn't know. I'll study them to understand them better.
Which option do you particularly use to perform in a production environment?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @Bernardes
We always use below for customers and works well.
sk122323: Log Exporter - Check Point Log Export
You can use that to send wherever you like...mostly, I know people use SIEM solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rock Thank you for the advice!
I'll try it in a lab before deploying in the customer, but it really seems to be the better and fast way to do that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank You all Guys for the great collaboration like always!
