Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bernardes
Advisor
Jump to solution

What is the best practices for export logs ?

Hello Mates!

Is there any documentation or best practice for exporting logs from SmartEvent/Log Server to an external server?

How do you recommend doing it?

Scripts via SSH? Export option via SmartConsole? Is there any other way? Any native integration with a backup solution?

Thank you all!

0 Kudos
2 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?

Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112 

 

Best Practice:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server

Refer also:

sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

CCSM R77/R80/ELITE

View solution in original post

(1)
the_rock
Legend
Legend

Hey @Bernardes 

We always use below for customers and works well.

sk122323: Log Exporter - Check Point Log Export

You can use that to send wherever you like...mostly, I know people use SIEM solution.

View solution in original post

(1)
5 Replies
Chris_Atkinson
Employee Employee
Employee

Are you looking to do it for archive purposes due to space / retention reasons or as an actual backup and do you have Management High Availability deployed?

Example Scripts:
https://community.checkpoint.com/t5/Management/Automate-Log-copy-to-external-SFTP/m-p/125112 

 

Best Practice:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS
sk98126: Best Practices - Configuration of logging from Security Gateway to Security Management Server / Log Server

Refer also:

sk92440: Move log files off Security Management Server for viewing at a later time
sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

CCSM R77/R80/ELITE
(1)
Bernardes
Advisor

Hello @Chris_Atkinson , thank you very much for your answer!

I need to do this just to keep the logs from a specific customer safe out of the SmartEvent /Log Server VM and if needed in the future, be able to reread them in SmartConsole.

I have read some of these SKs like:

sk122323: Log Exporter - Check Point Log Export
sk108902: Best Practices - Backup on Gaia OS

sk30569: Performing SCP (Secure Copy) between SecurePlatform/Gaia Servers

But the others that you sent I didn't know. I'll study them to understand them better.

Which option do you particularly use to perform in a production environment?

0 Kudos
the_rock
Legend
Legend

Hey @Bernardes 

We always use below for customers and works well.

sk122323: Log Exporter - Check Point Log Export

You can use that to send wherever you like...mostly, I know people use SIEM solution.

(1)
Bernardes
Advisor

@the_rock  Thank you for the advice!

 

I'll try it in a lab before deploying in the customer, but it really seems to be the better and fast way to do that.

0 Kudos
Bernardes
Advisor

Thank You all Guys for the great collaboration like always!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 30 Apr 2024 @ 08:00 AM (CDT)

    Central US: What's New in R82?

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 30 Apr 2024 @ 08:00 AM (CDT)

    Central US: What's New in R82?

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events