- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello all,
Check Point "Log Exporter" is an easy and secured method for exporting Check Point logs in few standard protocols and formats. It supports many SIEM vendors and it has some advanced features.
The Log Exporter main features and advantages are:
The Log Exporter is our main exporting tool and all new features will be added to it.
While saying that, I know that many of you are still using the old OPSEC LEA and I would like to understand the reasons for that and if there anything we can do to help you move forward to the log exporter.
Please share your thoughts.
Thanks!
Dan.
Very Interesting that you are listing LogRhythm as an Official Support by them as we have a Customer that has LogRhythm and whilst previously setup a Log Exporter for the 3rd Party that does the LogRhythm then am having to setup an OPSEC LEA for them so that they can work with the logs.
I am currently working to move to Log Exporter instead of OPSEC LEA. I'm hoping Log Exporter provides usable logs within SPLUNK than we are currently getting with OPSEC LEA. I personally find the logs too difficult to read. I rely mostly on Smart Log.
Log Exporter can export more than double logs per second than LEA. It is also utilize better the machine resources.
This was tested in Check Point and also in thousands of customers environments that already deployed the Log Exporter.
Hey Dave,
If you rather use our Check Point Logs view (new R80.20 SmartLog), why not simply use it, instead of exporting to splunk? (in either method)
What's missing for you?
Hi @Dan_Zada
Which of the two processes (LEA service or Log Exporter service) is more performance and resource intensive?
Did you test that at Check Point?
I am thinking here of companies with a lot of log traffic and MDM.
Which of the processes are multi core compatible?
Hello,
I have a question regarding Log Exporter feature. As I understood it is FORWARDING model rather than PULL model like the legacy OPSEC LEA.
We have MDS/MLM setup.
From time to time our gateways are logging locally (different issue we are looking at for long time already) and we configured them in SmartConsole to send these local log files to logging servers at specified schedule. These files are prefixed with gateway hostname. It seems that Splunk setup with legacy OPSEC LEA (unless some scripting employed) is unable to pull/parse different files than the actual log file on the logging server, so we are missing logs there.
My question is, when such log file is received from the gateway on the logging server and re-indexing is completed (or even before), will they be also automatically forwarded by Log Exporter to Splunk?
Thank you.
Hi,
I started using LEEF over LEA format for QRadar, and I find the push based to be more reliable. However, I cannot see complete logs, especially in IPS "Exploits" logs. I can only see source IP, but not the destination IP, destination port or source port in the logs in my qradar. Is there something I need to fix somewhere to get complete logs. I am using version R81.
In case if anyone is interested, set log type as semi-unified in expert mode, as command below
cp_log_export set name <name> read-mode semi-unified
command to view log exporters:
cp_log_export show
If log exporter is created using SmartConsole UI,
1. In Objects > Servers > Log Exporter/SIEM, select the object.
2. Right click on object and select Edit.
3. In Left Pane, select Data Manipulation.
4. Check "Aggregate log updates before export".
5. Publish and Install Policy.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY