- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
Check Point R81. The objective is to send logs to third party syslog (I'm speaking about logs appearing in SmartConsole under "Logs and Monitor").
I followed instructions reported here: Working with Syslog Servers; basically I added the syslog server under Security Gateway > Logs > Send logs and alerts to these log servers. So now there are two servers: Check Point Management and syslog server.
However no logs appears on the destination (syslog server); any idea on how to troubleshooting the issue ? I tried with a tcpdump (source: Security Gateway, destination: syslog server) but no traffic appears.
Is the solution applied (above), the right one to achieve the objective ?
I also discovered the Log Exporter that seems to be the same thing...? So now, which is the difference between Log Exporter vs syslog forward from Security Gateway ? (Yes, I already know the first one is on Management and the second one is from Security Gateway).
Thank you a lot,
Luca
Hey @lucafabbri365,
Did you change the logging properties of the gateways in step 3 (fwsyslog enable)? If you're not seeing any traffic in your tcpdump capture, it might be worth changing it to only include the destination ip of your syslog server, just incase your security gateway is behind a NATd address. Also, running fw ctl zdebug + drop | grep ip_of_syslog_server and see if you can see any drops there.
I'm not sure of the specifics between the two methods, but I much prefer the log_exporter route. I have two log_exporter instances running, which I find ery useful and gives me better control over what logs I wish to export.
The SK for this is SK122323
Hello AaronCP,
Log Exporter does what I really need and it is working fine.
The procedure for enabling syslog in Working with Syslog Servers article includes three point; the third one is fwsyslog that I didn't enable because I thought: "I don't want kernel logs". I suppose logs from Security Gateway are related to system, not "surfing". So I remain with Log Exporter.
Thank you,
Luca
Could you please share any details of how Log_exporter can select what logs/fields needs to send to third party (I'm using MS Sentinel) ?
Much appreciated your response!
Regards,
B
HI @BeaconBits
It is written in the https://support.checkpoint.com/results/sk/sk122323 arctile.
But I think, the parsing is much easier on the receiver side. If I were you, I would filter on the MS Sentinel side.
Think about this filter configuration. You will need to keep your eyes on it by every upgrade etc.
To be honest, I never use MGMT side filtering except the "ACTION" field. I send only the DROP actions somewhere, because of the amount of the logs 🙂
Akos
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY