Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Foranator
Explorer

2 questions regardins Logs

Hi

I have 2 questions in regards to logs. 

We are currently using 'Log Exporter' to send logs to our SIEM. 

We are seeing 2 weird behaviors : 

1. We are getting plenty of "Log Update". 
Where is the option to "aggregate logs before sending" ? Is it in the "log exporter" command line or somewhere in the Gateway Console ? 
Also, will this option consume a lot of ressources ? 

2. We are not seeing any logs from Threat Prevention blades 
Is it a "log exporter" problem? We are not filtering "in or out" anything... Could it be that our Checkpoint admin are not tracking anything done in those blades ? 

I'm new to checkpoint, so ELI5 🙂

Regards,

Foranator

 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

We send updates every 10 minutes or so on Active sessions and, to my knowledge, don’t have an option to change it.
If you’re not getting Threat Prevention logs as part of Log Exporter and you’re doing no filtering, then it’s because those blades are either not enabled or they aren’t logging anything.

Foranator
Explorer

Could it be that the "tracking"  is not activated for those blades ? 

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_LoggingAndMonitoring_AdminGu...

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events