- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
hello, is it possible to export logs from / var / log / messages in cef format to siem system?
It is known that it is not possible to do it through cp_log_export, and with sk102995 there is no way to change the format to cef.
See sk122323: Log Exporter - Check Point Log Export :
Formats: Syslog, Splunk, CEF, LEEF, Generic, JSON, LogRhythm, RSA
cp_log_export add name <Name> [domain-server <Name or IP address of Domain Server>] target-server <HostName or IP address of Target Server> target-port <Port on Target Server> protocol {udp | tcp} format {syslog | splunk | cef | leef | generic | json | logrhythm | rsa}
Hello, I looked at this sk, there is no way to export specifically / var / log / messages, the manufacturer says the same
Look into this discussion about getting logs from security gateway (not traffic related logs, but for example, /var/log/messages) from syslog:
Hi,
I am running R81.10 JHF 110 and only see this command on the Manager.
What about the Gateways?
Regards
Firewall logs are sent to the manager or log host. Therefore this command is mangement/logserver only.
Hi,
Thanks for your answer, but since from the gateways I can send syslog messages directly to other syslog servers apart the manager I imagined I could send them directly in CEF format.
One further question if you can help.
I managed to configure the manager to send in CEF format, mas the amount of information is huge, and I dont see no changes either I configure it to send all messages or just emergency.
Is there a way to configure the CEF level of messages?
Regards
Log Exporter can export Security Logs (not from /var/log/messages) in CEF format.
You can send OS logs to the Security Logs as @G_W_Albrecht mentions, which can then be exported as CEF.
However, I suspect the result of that may not be what you’re after.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY