Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bernardes
Advisor
Advisor
Jump to solution

What is the best practices for export logs ?

Hello Mates!

Is there any documentation or best practice for exporting logs from SmartEvent/Log Server to an external server?

How do you recommend doing it?

Scripts via SSH? Export option via SmartConsole? Is there any other way? Any native integration with a backup solution?

Thank you all!

2 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?

Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112 

 

Best Practice:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server

Refer also:

sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

CCSM R77/R80/ELITE

View solution in original post

the_rock
Legend
Legend

Hey @Bernardes 

We always use below for customers and works well.

sk122323: Log Exporter - Check Point Log Export

You can use that to send wherever you like...mostly, I know people use SIEM solution.

View solution in original post

5 Replies
Chris_Atkinson
Employee Employee
Employee

Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?

Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112 

 

Best Practice:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server

Refer also:

sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

CCSM R77/R80/ELITE
Bernardes
Advisor
Advisor

Hello @Chris_Atkinson , thank you very much for your answer!

I need to do this just to keep the logs from a specific customer safe out of the SmartEvent /Log Server VM and if needed in the future, be able to reread them in SmartConsole.

I have read some of these SKs like:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS

sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

But the others that you sent I didn't know. I'll study them to understand them better.

Which option do you particularly use to perform in a production environment?

the_rock
Legend
Legend

Hey @Bernardes 

We always use below for customers and works well.

sk122323: Log Exporter - Check Point Log Export

You can use that to send wherever you like...mostly, I know people use SIEM solution.

Bernardes
Advisor
Advisor

@the_rock  Thank you for the advice!

 

I'll try it in a lab before deploying in the customer, but it really seems to be the better and fast way to do that.

Bernardes
Advisor
Advisor

Thank You all Guys for the great collaboration like always!

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events