- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi CheckMates,
I read that, both syslog formats are supported ins R81.10
How can I switch between syslog formats (RFC 3164 (old) and RFC 5424 (new)?
Br
Akos
Is there a specific format / parsing issue or similar that you are trying to address?
Typically LogExporter is the most flexible approach per sk122323.
Hi Chris,
Exactly, the receiver side reported that, they can't parse the new format. Therefore I would like to swich the format to the older one.
After I switched it I will be able to point out, the error is on the receiver side.
That is my motivation.
BR
Akos
You realize this method only gives you limited Firewall-only logs, correct? (Nothing for other blades)
Log Exporter would be a much better way to export logs and offers other formats to export the logs.
Hi PhoneBoy,
To clarify the situation. I use cp_clog_export for exporting the logs.
BR
Akos
I assume you mean cp_log_export, which is Log Exporter.
However, what you provided a link to is not relevant to Log Exporter, but to a feature that allows sending specific traffic logs as syslog from the gateway itself (not the management).
Use the "format" option in Log Exporter to determine the format to send to the remote syslog server, which supports:
Parsing is the responsibility of the remote end.
Hi PhoneBoy,
Yes, I meant Log Exporter.
In the format settings
Is the deafult syslog format RFC 5424 format? If yes, can we change it somehow?
BR
Akos
I presume it is the default format, yes.
I don't believe you can change it.
What is the precise syslog server in use on the other end?
What is the precise CLI command you use to configure Log Exporter (or a screenshot of what's in SmartConsole)?
Hi Phoneboy,
The format part of the CLI command is "syslog"
The receiver syslog server's brand is Logness. It is an unique development. I do not hav the information, what is the base of this solution.
Akos
You might try "generic" and see if that provides a better result.
Hi,
Now it is much better than earlier was. Based on this, we asked the customer to contact the SIEM support to clarify this issue on the other side.
We can't change more things in log exporter.
Akos
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY