- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello,
We are an MSSP, and most of our customers have an R80.40.
At one of our customers' site, for example, we have configured a log exporter to send logs from the management server to a QRadar collector at the same site. For some reason we cannot see any audit logs being sent to us.
Some of our customers still forward logs using OPSEC\LEA protocol, and while using this protocol I can see the audit logs in our SIEM (QRadar).
While checking any of the customers using Syslog protocol, I cannot find event one audit log being sent to us.
Is there any known issues exporting audit logs while using log exporter and Syslog protocol?
Thank you.
Please see if related to the following SK:
Not all logs are exported when log exporter is configured on Log Server/Multi-Domain Log Module
HTH
Tal
I don't know if this is the case.
I mean, the log exporter is configured to send the logs to a QRadar log collection server. The logs are being sent immediately, but as I have mentioned, we cannot see audit logs.
Then contact TAC and either get the hotfix or a reason why that is not working!
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY