- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi,
I noticed that some audit logs are sent to the siem while others aren't when using dedicated log servers, for example - if the operation is "Incident Viewed", "Set Object", "Delete Object", so basically the least important audit logs, then the Origin Log servers is the dedicated Log Server and the logs are sent to the SIEM.
But if the Operation is "Publish", "Delete Rule", "Create Rule" or "IPS Update" Than the Origin Log Server is usually the SMS itself and these audit logs are not being sent to the SIEM (as only the dedicated servers are sending the logs).
I would like to send with log exporter all the audit logs to the siem even when using dedicated log servers, including those where the Origin log server IP is the SMS itself, as they contain info about important changes being made to IPS and access control configuration. How can that be done?
I believe you can configure Log Exporter on the SMS in this case to export the relevant logs directly (assuming they are there).
Thanks for the reply, so if I understand correctly, the log exporter should be configured both on the dedicated log servers and on the SMS, but the SMS should be configured to only send Audit logs in this case, as not to duplicate logs sent to the SIEM?
Is there a one liner command for log exporter to only export audit logs or does it require manipulation of the file targetConfiguration.xml?
The Log Server and the SMS should have different logs, thus there shouldn't be any overlap.
That said, I believe you can just configure Log Exporter to send audit logs.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY