- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have configured the smartevent server with the log exporter object and is sending the data to Qradar. The format is LEEF as expected and inside the default LeefFieldsMapping.xml we see <field><origName><severity</origname> which would replace the value to 0-10 however inside the data capture we dont find any severity field.
Is this not being send by default and how can we include this for the LEEF log exporter to Qradar?
note:in smartconsole we do see the correlated event with proper severity and we also located the event (without severity) in packet capture send to Qradar
I would suggest to contact TAC to get this working !
<field><origName><severity</origname> looks like a typo?
Maybe add in a > at the end of severity?
The default xml includes this so I would assume that it would include severity but we cannot locate that inside the pcap data. Also in general smartevents correlated events are being send in LEEF but nothing it actually being "received" at Qradar side which is under review by this vendor. The SMS is already working fine out of the box. At this moment i am focussing on this severity field which needs to be included and yes of course I could engage TAC case for this.
I also left a note here
https://community.checkpoint.com/t5/Management/Log-Exporter-LEEF-Field-Mappings/td-p/48905
<field><origName>severity</origName><dstName>sev</dstName>
<callback>
<name>replace_value</name>
<args>
<arg key="default" value="0"/>
<arg key="0" value="0"/>
<arg key="1" value="2"/>
<arg key="2" value="5"/>
<arg key="3" value="8"/>
<arg key="4" value="10"/>
</args>
</callback>
</field>
that was probably my typo sorry I mean in this article see below for correct XML content which is not working
Suggest a TAC case: https://help.checkpoint.com
We got answer from supplier Qradar and they say that the correlated events are send to Qradar with Product Name VPN-1 Power/UTM whereas they would expect it to be VPN-1 Firewall-1 (which does work). Gonna share these details with TAC and probably some fix is needed in the code for it to integrate correctly.
in dump i see it is formatted like this LEEF:2.0|Check Point|VPN-1 & FireWall-1| and this is not parsed at Qradar side
I suggest contacting Qradar to resolve this issue as we are providing the data to them in the correct format.
Yes you are right events are filtered at their side also to prevent it from overloading, what we want is to only send the Smartevent correlated events to syslog server and now looking into a way to implement automatic reactions with external script. Will open another question about that to define this script with logger action.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 10 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY