Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
drkmtr
Explorer
Jump to solution

Configuring syslogs to SIEM for Spark SMB devices

Hi all,

We currently have dozens of Quantum Spark devices in the field and looking at a few comprehensive SIEM/SOAR/SOC solutions to enable comprehensive coverage across our clients environments.

Without purchasing Smart-1 for these clients (required for Check Point MDR integration), are we able to send syslogs to an external/internal collector (e.g., Adlumin collector, Huntress Agent)?

If this is possible, how is this achieved? Is it via disabling cloud services and then CLI? In your opinion, what is the down sides to disabling cloud services apart from managing firmware upgrades (currently via Infinity), policies etc.

I hope that makes sense and thanks for any assistance/guidance in advance.

0 Kudos
1 Solution

Accepted Solutions
sigal
Employee
Employee

Hi,
You should be able to send logs to syslog server while keeping cloud services.
This can be done under Logs and Monitoring -> External Log Servers -> Syslog Servers.

Thanks.

View solution in original post

0 Kudos
(1)
3 Replies
PhoneBoy
Admin
Admin

Exporting security logs via syslog is your only option.
Note it is not possible to change the format the logs are sent in, which might be problematic for some solutions to ingest.

0 Kudos
sigal
Employee
Employee

Hi,
You should be able to send logs to syslog server while keeping cloud services.
This can be done under Logs and Monitoring -> External Log Servers -> Syslog Servers.

Thanks.

0 Kudos
(1)
drkmtr
Explorer

Thank you to everyone that responded.

This was very easy and a perfect solution. I have configured External Log Servers -> Syslog Servers and added the IP and Port of the Huntress agent, which works seamlessly.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events