Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
drkmtr
Explorer

Configuring syslogs to SIEM for Spark SMB devices

Hi all,

We currently have dozens of Quantum Spark devices in the field and looking at a few comprehensive SIEM/SOAR/SOC solutions to enable comprehensive coverage across our clients environments.

Without purchasing Smart-1 for these clients (required for Check Point MDR integration), are we able to send syslogs to an external/internal collector (e.g., Adlumin collector, Huntress Agent)?

If this is possible, how is this achieved? Is it via disabling cloud services and then CLI? In your opinion, what is the down sides to disabling cloud services apart from managing firmware upgrades (currently via Infinity), policies etc.

I hope that makes sense and thanks for any assistance/guidance in advance.

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Exporting security logs via syslog is your only option.
Note it is not possible to change the format the logs are sent in, which might be problematic for some solutions to ingest.

0 Kudos
sigal
Employee
Employee

Hi,
You should be able to send logs to syslog server while keeping cloud services.
This can be done under Logs and Monitoring -> External Log Servers -> Syslog Servers.

Thanks.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events