Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HPACHPANDE
Explorer

Need Help on log forwarding for specific log forwarding to SIEM (User activity,Configuration chang)

Hello Folks,


We are receiving logs from all blades As mentioned below 

 
 

VPN-1 & FireWall-1
Anti Malware
New Anti Virus
Syslog
SmartDefense
Security Gateway/Management
WEB_API
Identity Awarenes
Threat Emulation


But Concern here is we are not seeing any user login/logout failed/success events. Also no any log is recorded for Firewall Configuration change.

Kindly let me know how we can get those logs in Qradar SIEM

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

The logs you receive depend entirely on the Log Exporter configuration.
How precisely is this configured?
What version/JHF is the management?

You did not list Mobile Access in the above "blades" list which I believe is how Remote Access VPN logins will show up.
Audit logs must be exported explicitly.

0 Kudos
Firewallhelpdes
Explorer

change report are not forwarding to q-radar. But inbound and outbound traffic is forwarding properly. Kindly suggest how to check further.

0 Kudos
_Val_
Admin
Admin

Change reports as in policy change logs?

Audit logs reside on the management where the changes are done. If you configure your Log Exporter on that management, they should be forwarded, unless you excluded them in the initial configuration. If you export logs from your log server and not the management server, then you may want to forward them from your management server to the log server as described sk107459, or to configure an additional log exporter on your management server directly.

0 Kudos
PhoneBoy
Admin
Admin

Review the targetConfiguration.xml file to see if you are sending audit logs.
More details: 
https://support.checkpoint.com/results/sk/sk122323 

0 Kudos
Upcoming Events

    CheckMates Events