Hi
I have 2 questions in regards to logs.
We are currently using 'Log Exporter' to send logs to our SIEM.
We are seeing 2 weird behaviors :
1. We are getting plenty of "Log Update".
Where is the option to "aggregate logs before sending" ? Is it in the "log exporter" command line or somewhere in the Gateway Console ?
Also, will this option consume a lot of ressources ?
2. We are not seeing any logs from Threat Prevention blades
Is it a "log exporter" problem? We are not filtering "in or out" anything... Could it be that our Checkpoint admin are not tracking anything done in those blades ?
I'm new to checkpoint, so ELI5 🙂
Regards,
Foranator