Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sagar_Manandhar
Advisor

Send specific log to SEIM

Hi,

Is there the way for management server to send only specific logs ( like critical ips log only,high bandwidth application and url log) to SIEM ?

We are trying different SEIM product for POC (proof of concept) but due to huge log the device is not able to process the log as for POC they are using the low end devices.

Regards,

Sagar Manandhar

 

1 Reply
Alejandro_Mont1
Collaborator

Are you using LEA or Log Exporter? If using LEA I believe logs are pulled, not sent from the Check Point device so there would be nothing on the management server to change. If using Log Exporter sk122323 under Advanced Deployment there is a Filter Parameters paragraph that details how to exclude firewall blade logs.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 08:00 AM (CDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Tue 23 Apr 2024 @ 08:00 AM (CDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events