Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Yair_Herling
Employee
Employee

R80.20 Log Exporter Feature

This video elaborate on Check Point's R80.20 log exporter feature, introducing an easy and secure method for exporting Check Point logs to 3rd party SIEM applications, using various protocols (like TCP or UDP) and formats (like syslog, CEF, or LEEF)

10 Replies
Daniel_
Advisor

Splunk also has a Opsec Connection (LEA) to receive the logs. Is there an advantage to use this export feature?

0 Kudos
PhoneBoy
Admin
Admin

While we will continue to support LEA for the time being, Log Exporter is going to be the recommended method for exporting logs to third party SIEMs going forward.

Don_Paterson
Advisor

Thanks. Is there an SK for this? Perhaps that and a link to that or to the admin guide with the info about that would  be beneficial in this thread.

Don

0 Kudos
PhoneBoy
Admin
Admin

The official SK: Log Exporter - Check Point Log Export 

The "canonical" thread on CheckMates: Log Exporter guide

Don_Paterson
Advisor

And so the loop is closed and it's all brought together.

Nice one, thank you Dameon.

Prashant
Participant

Does log exporter on R80.20 configuration on MLM sends logs with source IP of each configured CLM.

We had this requirement for long and lately few months back R&D suggested that it will be in R80.20.

We recently upgraded to R80.20 though still see MLM ip as source on syslog for all CLM.

We want separate connection with each CLM IP itself.

Pls suggest

0 Kudos
Martin_Valenta
Advisor

It's not in place in r80.20, in our case we send traffic from each CLM via different port to our SIEM and based on port we know from which CLM logs are comming to SIEM.
0 Kudos
Prashant
Participant

Thanks Martin -

 

I got the idea, though as I checked, if I use TCP as protocol for Syslog, I can see CLM IP as desired but not the case with UDP(though need to check myself).

 

Will update final result. 

0 Kudos
Martin_Valenta
Advisor

It doesn't matter if tcp/udp it's still flows from MLM server ip.
0 Kudos
Prashant
Participant

I checked it on R80.20 MLM, I could see connection with CLM IP if used with TCP.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events