Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
K_montalvo
Advisor
Jump to solution

R80.30 Gateway logs to Splunk

Hello my friends,

I would like to send logs to a new Splunk server im running R80.30 on a 5000 Stand Alone Appliance. My question is if i configure the syslog server as in the link below would i still be able to view logs as i do day to day via Smart Console>Logs & Monitor ?

link https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_LoggingAndMonitoring_AdminGu...

If available other configuration document for this solution kindly share,

Thanks!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

This particular approach is not recommended as you only get firewall logs (not logs from other blades).
Also, this particular approach is not integrated with Splunk the way Log Exporter is, which is the recommend approach.
You'll still be able to see the logs in your management as you do today.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

View solution in original post

4 Replies
PhoneBoy
Admin
Admin

This particular approach is not recommended as you only get firewall logs (not logs from other blades).
Also, this particular approach is not integrated with Splunk the way Log Exporter is, which is the recommend approach.
You'll still be able to see the logs in your management as you do today.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

K_montalvo
Advisor

Hello @PhoneBoy 

Thank you for the fast response, i run the commands below but received and error. Can you verify and provide me some guidance of what im doing wrong and/or if im missing something.

> cp_log_export add name splunk_prod target-server X.X.X.X target-port 12001 protocol tcp format splunk read-mode semi-unified
CLINFR0329 Invalid command:'cp_log_export add name splunk_prod target-server X.X.X.X target-port 12001 protocol tcp format splunk read-mode semi-unified'.
>

 

Thanks!

0 Kudos
PhoneBoy
Admin
Admin

The command must be entered in expert mode.

K_montalvo
Advisor

Yikes, that worked perfect!

Many many thanks buddy!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events