Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
harshnagar
Explorer

High EPS from Checkpoint Firewall on SIEM

Hello Team,

We have recently integrated Checkpoint FW with our Qradar SIEM for SOC Monitoring Prospective and we are experiencing a high spike in EPS ranging from 5000 - 7000 during Business hours, as we have forwarded all the logs with severity level as "all", so this might be possible that Checkpoint is forwarding all the logs which are irrelevant for Security, now we want to remove those logs which are not necessary as per security point of view, please suggest what configuration can help us to resolve this issue without losing any important logs related to security, also suggest can we bifurcate the current logs we are receiving from Checkpoint on our Qradar by Severity of each log, which will help yes to differentiate how much logs are informational, critical, etc.

0 Kudos
1 Reply
Chris_Atkinson
Employee Employee
Employee

Please review the filtering options within log exporter per the below.

Also confirm if you a logging both connection & session logs?

https://sc1.checkpoint.com/documents/Log_Exporter/EN/Content/Topics/Filter-Configuration.htm?tocpath... 

https://support.checkpoint.com/results/sk/sk122323

 

CCSM R77/R80/ELITE
0 Kudos
Upcoming Events

    CheckMates Events