- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello,
We have deployed recently in our environment r88.10. I was poking around to see if I'm able to send syslog events matching only Up/Down of the FW interface to an external Syslog Server(elastic), but no luck so far .
Can somebody give a tip how to do it?
Kind regards.
I think you should define syslog target here:
And may be enable snmp traps for interface Up/Down, if you do not see it in default syslog output:
Did you read sk87560 How to configure R77.30 Security Gateway on Gaia OS to send FireWall logs to an external Syslog server ? This is for R77.30 only, but contains the following two statements for R80.10:
1. To export Check Point FireWall and Audit logs from a Security Management Server / Multi-Domain Security Management Server / Log Server to external Syslog servers, refer to sk115392 - How to export Check Point logs to a Syslog server using CPLogToSyslog.
2. To export Check Point FireWall logs directly from a Security Gateway / Cluster Member R80.10, contact Check Point Support to get a Hotfix (Issue ID 02646044).
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY