- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: how to forwad firewall log to 3rd party syslog...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
how to forwad firewall log to 3rd party syslog server
Hi.
I'd like to forward firewall log to 3rd party syslog server.
but only get as follows.
Mar 5 10:15:12 192.168.90.8 CP-GW
Mar 5 10:15:12 192.168.90.8 CP-GW
Mar 5 10:15:12 192.168.90.8 CP-GW
Mar 5 10:15:12 192.168.90.8 CP-GW
probably I need something change on rsyslog.conf
anybody know how to fix it ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The best way to do this at the moment is using the CpLogToSyslog tool: How to export Check Point logs to a Syslog server using CPLogToSyslog
In the near future, a different tool will be available for this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found issue CPlog2Syslog port 18184 crash and waiting TAC provide new tool.
Hope the new tool can solved my issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm waiting too ....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The new tool works on my lab. I'll deploy on production next week.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We could solve this problem
rsyslog.conf like follows.
$template RawMsgOutputFormat, "%TIMESTAMP% %HOSTNAME% %rawmsg%\n"
:fromhost-ip,isequal,"IP-ADDR" -/var/log/fw/fw.log;RawMsgOutputFormat
hope someone's help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
A new log exporting tool has been released. This tool will be replacing CPLogToSyslog.
You can find all relevant details in Logs Exporter - Check Point Logs Export.
It can work on any port in either TCP or UDP.
Regards,
Yonatan
