- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Everyone,
I have a Smart-1 5150 device that manage 90 checkpoint gateway. I want to integrated it with LogRhythm SIEM.
I was create a host object for LogRhythm SIEM with it IP.
I was create a OPSEC Application for it and also pull certificates from Check Point Smart-1 devices.
Now i need to provide the information below on LogRhythm SIEM :
"OPSEC_APP_SIC_DN" is the DN name in OPSEC Application which is "CN=LogRhythm-XM,O=CP-Smart1..ksmkv" in my picture. Is this corect ?
"lea_server auth_type" is sslca. Is this only 1 type is sslca or any orther type ?
"LOG_SERVER_DN" i not sure where to collect this infor ? i going to the web portal of Smart-1 device and see the DN in Certificate Authority tab as below :
is this the right DN for "LOG_SERVER_DN". Since Smart-1 devices í manage all orther firewall, the "LOG_SERVER_DN" is the DN of Smart01 device, right ?
Cause after configure, i still can't receive any log on LogRhythm SIEM about Check Point OPSEC. Please help me solve this issue. Thanks!
Dear Maarten_Sjouw,
Thanks for your response, i will check the sk you refer and give it a try. Have a nice day!
Hi,
In the last few weeks we developed new integration with LogRhythm, based on the log exporter.
If you want, we can add you to the EA program so you will enjoy simple and improved integration between Check Point and LR.
We will contact you personally about it.
Thanks!
Dan.
Dear Dan_Zada,
Yes, it would be great. Please add me to it. I have both Check Point and LogRhythm in my System and i really want to make it work together.
Hi @quanglnh
I added you to our EA program.
I just sent a message with more information about it - please check your CheckMates inbox.
Regards,
Shay
Thanks alot,
I hope we can solve this issue soon!
Hi Shay
We‘re in the same boat - it would be great if you can add me also to the EA to provide me some additional informations.
Thank you.
Roland
Hi @startoff
I will ask the relevant people from my group to contact you.
Dear Dan
Kindly add me also i have a similar setup
Hello Dan_Zada,
Kindly add me to EA program.
Regards
Titus
Dear Dan
Kindly add me to the EA program
Hi Dan
Please can you add us to this EA program?
Many thanks
Stuart
Is this EA program the OPSEC LEA for 7.4.1+ Log Processing Policy or something different/new/improved? We'd like to hear more about this program.
Also, I've been searching the help site and cannot find whether the Checkpoint OPSEC application for collection supports Server Core 2019 for the Agent collector server OS?
Thank you
Eric
Hey Dan,
Any way I can get in on this EA program as well?
Chris
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY