- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Team,
We've been trying to set things up to automate the log upload process for Microsoft Cloud apps discovery. We first tried setting the checkpoint log format to Syslog and set the Microsoft receiver type to syslog. But we saw that the Microsoft side did not parse it correctly. Return it as an error.
Is someone who makes it happen, except using a custom log parser? We try to make it by using a continuous log upload procedure.
Regards
Can you send us an error, please?
Andy
Hi Andy,
we have uploaded successfully, but microsoft did not parse it and throw the above error out as you will see. microsoft side say that they support checkpoint. But they can not parse it. We want to use the feature.
End of the line is disappear in the pic, it is
CHECKPOINT_CEF_SYSLOG
So its complaining about the log format. Can you send output of cp_log_export show?
Andy
name: MicrosoftCloudApp-logcollector
enabled: false
target-server: 10.X.X.X
target-port: 514
protocol: udp
format: syslog
read-mode: semi-unified
export-attachment-ids: false
export-link: false
export-attachment-link: false
time-in-milli: false
export-log-position: false
reconnect-interval: Not configured, using default
Not sure then why it does not parse it on the other side, since you selected syslog. Did you reach out to their support?
Andy
nope, the checkpoint side has already published a SK for that purpose?https://support.checkpoint.com/results/sk/sk177524
However, some say that they achieve this by using the CEF format. https://community.checkpoint.com/t5/Management/Log-Exporter-to-Microsoft-Defender-for-Cloud-Apps/td-...
We also tried it, but still no chance. I just open it to check if someone who is achieve also.
Regards
Not sure if that sk would be 100% applicable in your case, but I would certainly try with different formats to see if it makes any difference.
Andy
When I followed up on the SK, I saw the Microsoft Side report. They correctly parse the data I have uploaded. But I just want to do it with the auto way.
Thats fine for the report, but question is does it work regardless of what log format you use?
Andy
You need a CSV file from the checkpoint side by using logexport. then you have to tell the Microsoft which column header you need to parse and also the delimiter. just it. then you will upload the CSV file you get from the checkpoint. It will upload and try to parse it. and will notify you.
K, sounds good.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY