- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- cp_log_export Mgmt Audit log forwarding?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
cp_log_export Mgmt Audit log forwarding?
Hi Guys,
I am forwarding cp_log_export package to forward CheckPoint logs to our SIEM in CEF format. However would like to know since those are all traffic logs can I forward Mgmt Audit logs as well through cp_log_export to my SIEM?
if not is there any alternate way to achieve the same?
Thanks and Regards
Blason R
CCSA,CCSE,CCCS
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Looks like I may have been mistaken: audit logs should be included.
See the discussion here: https://community.checkpoint.com/thread/7248-log-exporter-guide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently, audit logs can only be forwarded thru LEA, which is how SIEMs have traditionally integrated with our product.
You will need to consult with your SIEM vendor on the exact procedure for this.
We do plan to integrate audit logs support into Log Exporter in an upcoming release.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Looks like I may have been mistaken: audit logs should be included.
See the discussion here: https://community.checkpoint.com/thread/7248-log-exporter-guide
