Hi All,
Yes I know, Check Point is working or doing a survey on how to forward events to 3rd party SIEM tools.
However we can't wait this long, currently we filter the logs using the logforwarder to our SIEM (using Syslog), however data ingest is reasonable.
Furthermore, our deployement consists of a reasonable amount of Quantum Gateways which forwards those logs to our SmartEvent server within an MDS system. So integration with Smart-1 Cloud is an feasible option right now.
We could however forward the logs only to the Smart-1 Cloud, but we're unsure if we can create a link to our SIEM solution. Does anyone created a solution to forward events and alerts only from an mostly onprem environment to a 3rd party SIEM.
Other then forwarding the raw syslogs into the 3rd party SIEM datalake and do the filtering right there.
btw we do some filtering on the SmartEvent logforwarder also, however this is pretty cumbersome.
Hope anyone can help, thanks for the assistance in advance.
Greetz, Johan