- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have configured the smartevent server with the log exporter object and is sending the data to Qradar. The format is LEEF as expected and inside the default LeefFieldsMapping.xml we see <field><origName><severity</origname> which would replace the value to 0-10 however inside the data capture we dont find any severity field.
Is this not being send by default and how can we include this for the LEEF log exporter to Qradar?
note:in smartconsole we do see the correlated event with proper severity and we also located the event (without severity) in packet capture send to Qradar
I would suggest to contact TAC to get this working !
<field><origName><severity</origname> looks like a typo?
Maybe add in a > at the end of severity?
The default xml includes this so I would assume that it would include severity but we cannot locate that inside the pcap data. Also in general smartevents correlated events are being send in LEEF but nothing it actually being "received" at Qradar side which is under review by this vendor. The SMS is already working fine out of the box. At this moment i am focussing on this severity field which needs to be included and yes of course I could engage TAC case for this.
I also left a note here
https://community.checkpoint.com/t5/Management/Log-Exporter-LEEF-Field-Mappings/td-p/48905
<field><origName>severity</origName><dstName>sev</dstName>
<callback>
<name>replace_value</name>
<args>
<arg key="default" value="0"/>
<arg key="0" value="0"/>
<arg key="1" value="2"/>
<arg key="2" value="5"/>
<arg key="3" value="8"/>
<arg key="4" value="10"/>
</args>
</callback>
</field>
that was probably my typo sorry I mean in this article see below for correct XML content which is not working
Suggest a TAC case: https://help.checkpoint.com
We got answer from supplier Qradar and they say that the correlated events are send to Qradar with Product Name VPN-1 Power/UTM whereas they would expect it to be VPN-1 Firewall-1 (which does work). Gonna share these details with TAC and probably some fix is needed in the code for it to integrate correctly.
in dump i see it is formatted like this LEEF:2.0|Check Point|VPN-1 & FireWall-1| and this is not parsed at Qradar side
I suggest contacting Qradar to resolve this issue as we are providing the data to them in the correct format.
Yes you are right events are filtered at their side also to prevent it from overloading, what we want is to only send the Smartevent correlated events to syslog server and now looking into a way to implement automatic reactions with external script. Will open another question about that to define this script with logger action.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY