- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
so how do i go about troubleshooting the process?
[Expert@FW-MGMT01:0]# tcpdump -neei any port 18184 and host 10.7.x.x tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
^C
0 packets captured
0 packets received by filter
0 packets dropped by kernel
[Expert@FW-MGMT01:0]# tracert 10.7.x.x
traceroute to 10.7.x.x (10.7.x.x), 30 hops max, 40 byte packets
1 10.7.x.x (10.7.x.x) 0.631 ms 0.759 ms 0.897 ms
2 secopslogrhyp01.flyfrontier.com (10.7.x.x) 0.412 ms 0.420 ms 0.457 ms
[Expert@FW-MGMT01:0]# cpca_client lscert -kind SIC -stat Pending | grep -A 3 LogRhythym
[Expert@FW-MGMT01:0]# grep Spawn_LEA $CPDIR/registry/HKLM_registry.data
:Spawn_LEA ("[4]1")
As you can see from the above outputs, it seems tcpdump shows no traffic no idea what to do next now, tracert shows nothing blocking traffic on the way (only 1 device in between which is not a firewall, probably a router), for certificate pending i ran the command as shown and shows no output (no idea what that means) and as you can see for the grep spawn command it seems lea_spawning is already enabled, now what to do next? do i log into the logrhythym server and restart it or something? (logrhythym server is running on a windows 2016 machine with more than enough storage space(has about 24tb of space) but when i look at the relevant drive which is named as Log which im assuming is the drive used to store the logs it shows 0.98tb free of 0.99tb that means nothing is being logged right? also other drives have most of the space free as well).
Hello,
Netstat shows no connections to the logrhythym server, i only see established, close_wait, time_wait, fin_wait2, and then listen states, all listen states are to dest address 0.0.0.0:* and none of those above mentioned connections are to the logrhythym server(ran the command on the primary mgmt server btw), so you asked if i did any troubleshooting on the server side, what sort of troubleshooting should i do?
Log Exporter is the recommended method to export logs. See below.
Pre-R80.40 versions need a special hotfix installation in order to support LogRhythm.
ok i did open up a tac case and even he wasnt able to figure out the issue, so sent a bunch of log files and cpinfo so they can look into it, meanwhile i will definitely look into setting up the log ex[porter, just dont know if setting it up will be too complpicated or something, hopefully its doable for me.
Hi @kb1
I would be happy to assist you with Log Exporter configuration and integration with LogRhythm.
Can you please send me email to shayhi@checkpoint.com and we will take it offline together?
I would like to understand what step were already taken in Log Exporter aspect.
Regards,
Shay
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 10 | |
| 10 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY