- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi all,
i have r80.30 domain and r77.30 gateways; Do you know if it is possible to send checkpoint logs, in syslog format, from r77.30 gateways to Qradar siem ?
i have configured it when my domain was in r77.30 by adding r77 addon. But now my domain is in r80.30 so i don’t know if it is still possible or not.
thx a lot for your reply.
Unless mistaken...
Most recommended: Logging from mgmt/log server w log exporter (some functions can only be achieved this way)
Secondary option: The logging from the GW existed in R77.30 but its central mgmt required plug in that was missing in initial R80x. The central management returned back in R80.20 (and since its main train, it remains in releases after) - Howto? Look for log servers and see that you can define log server that is syslog server...
The way to send logs to external system is log exporter from the management.
Yes, ... this works on R80.30 even if your GW version is old
Hi @Dorit_Dor ,
If i'm right log exporter send logs only from management.
My question is how to send logs directly from gateway ?
Kind regards.
Unless mistaken...
Most recommended: Logging from mgmt/log server w log exporter (some functions can only be achieved this way)
Secondary option: The logging from the GW existed in R77.30 but its central mgmt required plug in that was missing in initial R80x. The central management returned back in R80.20 (and since its main train, it remains in releases after) - Howto? Look for log servers and see that you can define log server that is syslog server...
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY