Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
furi
Explorer

Checkpoint Log exporter to Microsoft Cloud apps discovery

Hi Team,

We've been trying to set things up to automate the log upload process for Microsoft Cloud apps discovery. We first tried setting the checkpoint log format to Syslog and set the Microsoft receiver type to syslog. But we saw that the Microsoft side did not parse it correctly. Return it as an error.

 

Is someone who makes it happen, except using a custom log parser? We try to make it by using a continuous log upload procedure.

 

Regards

0 Kudos
11 Replies
the_rock
Legend
Legend

Can you send us an error, please?

Andy

0 Kudos
furi
Explorer

Hi Andy,

IMG_8224.jpeg

 we have uploaded successfully, but microsoft did not parse it and throw the above error out as you will see. microsoft side say that they support checkpoint. But they can not parse it. We want to use the feature.
End of the line is disappear in the pic, it is 

CHECKPOINT_CEF_SYSLOG

0 Kudos
the_rock
Legend
Legend

So its complaining about the log format. Can you send output of cp_log_export show?

Andy

0 Kudos
furi
Explorer

name: MicrosoftCloudApp-logcollector
      enabled: false
      target-server: 10.X.X.X
      target-port: 514
      protocol: udp
      format: syslog
      read-mode: semi-unified
      export-attachment-ids: false
      export-link: false
      export-attachment-link: false
      time-in-milli: false
      export-log-position: false
      reconnect-interval: Not configured, using default

0 Kudos
the_rock
Legend
Legend

Not sure then why it does not parse it on the other side, since you selected syslog. Did you reach out to their support?

Andy

0 Kudos
furi
Explorer

nope, the checkpoint side has already published a SK for that purpose?https://support.checkpoint.com/results/sk/sk177524

However, some say that they achieve this by using the CEF format. https://community.checkpoint.com/t5/Management/Log-Exporter-to-Microsoft-Defender-for-Cloud-Apps/td-...

We also tried it, but still no chance. I just open it to check if someone who is achieve also.

Regards

0 Kudos
the_rock
Legend
Legend

Not sure if that sk would be 100% applicable in your case, but I would certainly try with different formats to see if it makes any difference.

Andy

0 Kudos
furi
Explorer

When I followed up on the SK, I saw the Microsoft Side report.  They correctly parse the data I have uploaded.  But I just want to do it with the auto way.

0 Kudos
the_rock
Legend
Legend

Thats fine for the report, but question is does it work regardless of what log format you use?

Andy

0 Kudos
furi
Explorer

You need a CSV file from the checkpoint side by using logexport. then you have to tell the Microsoft which column header you need to parse and also the delimiter. just it. then you will upload the CSV file you get from the checkpoint. It will upload and try to parse it. and will notify you.

0 Kudos
the_rock
Legend
Legend

K, sounds good.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events