- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Logs forwarding
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Logs forwarding
Can we send Check Point 730 Appliance system and security logs to AWS EC2 system directly through syslog configuration ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Security Logs from SMB can only be forwarded through an OPSEC LEA connection (not syslog).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any idea how I can configure the logs from CP to AWS EC2 instance through OPSEC LEA. Do I need to configure anything extra as I don't have CP SMS licence in my environment. Please share some details / documents which can be helpful here. Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That SMS could run in AWS using a PAYG license.
Once on an SMS you could use Log Exporter to send the logs via syslog wherever it needs to go.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Actually, you CAN export security logs via syslog, but it will be plain UDP syslog, without any security or guarantee of delivery.
Also, the format is not very friendly and you'd need to customize your own filter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure what version we started supporting it, but yes includes the option to send security logs. Enable Show obfuscated if needed. As Pedro says not sent securely and will need to parse them to do any reporting on them.
The central log server may be the better option for both of these reasons.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yep, it's been around for a while.
I am logging to NAS-based syslog in my lab from standalone 1430:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And it must be a relatively recent feature.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think it is available since R77.20.80.
