- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
So we've been exporting our gateway *audit logs* regularly in 77.30 to splunk, and now we upgraded to 80.10.
With the new API, we are wondering if it's possible to export the logs of the API.
Let's say for example, if someone ran a "show group" command from the management server, it's log would be exported and seen on splunk.
Is it possible?
Have you tried the Log Exporter for that purpose (sk122323)?
You would need to install the Check_Point_R80.10_Log_Exporter_T50_sk122323_FULL.tgz package first as far as I can see and then I would refer you to the most relevant section for you:
Splunk
It is recommended to use Check Point App for Splunk when exporting logs to Splunk server.
For more information about installation and deployment, please see the Check Point App for Splunk User Guide.
In addition, in order to configure an encrypted connection, do the following:
1. Generate server pem file:
cat syslogServer.crt syslogServer.key RootCA.pem > splunk.pem
2. Update the inputs.conf file on the Splunk server
vi /opt/splunk/etc/apps/search/local/inputs.conf
[SSL]
serverCert = /etc/ssl/my-certs/splunk.pem
sslPassword = <challenge password>
requireClientCert = true
[tcp-ssl://<port>]
index = <index>
3. Update the server.conf file on the Splunk server
vi /opt/splunk/etc/system/local/server.conf
[sslConfig]
sslRootCAPath = /etc/ssl/my-certs/RootCA.pem
4. Restart Splunk
/opt/splunk/bin/splunk restart
I hope this helps.
Hi, i am using log exporter but the only logs it exports are clish logs or ssh connections, but not the linux expert commands. is there any other configuration i need to make?
ok, what about API commands through the expert, are they logged? it seems odd to me that you can't see what was searched with api...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 17 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY