Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LogRe
Explorer

"web_server_type" field is not output in URL filtering log

The "web_server_type" field is not output in the URL filtering log, and I would like to know how to get it in CheckPoint R81.20 Take26  to 76.

I have created a policy that allows access to a specific domain using the URL filtering feature.

I have specified "Extended Log" for Track and enabled the "Accounting" feature.

When accessing the allowed domains, the web server returns a header like "Server: Apache".

In this case, web_server_type="Apache" is supposed to be output in the log, but it is not.

0 Kudos
5 Replies
_Val_
Admin
Admin

Are you working with the Check Point logs or those forwarded to an external SIEM?

0 Kudos
LogRe
Explorer

Sorry for the lack of information.
You are correct, we are using the Log Exporter function to forward the Generic logs to the syslog server.

0 Kudos
_Val_
Admin
Admin

Okay, now this makes sense. You must explicitly enable forwarding for this field in the Log Exporter configuration. If I remember correctly, this field is not forwarded by default.

Please look into sk122323 for more details.

0 Kudos
LogRe
Explorer

Thank you very much. I will check it.

0 Kudos
LogRe
Explorer

Unfortunately, we were unable to resolve the issue.
I checked “Fields Configuration” in sk122323.
I edited the FieldsMapping.xml as attached for testing , but the “web_server_type” is not output in the URL filtering log.
Attached is the log that is being output now.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events