Use https://seceonhelp.freshdesk.com/support/login to access updated Knowledge Base Articles, Submit Technical Support Tickets and Review Status of submitted support tickets.

Checkpoint Harmony Exporting Logs

Overview

Check Point Log Exporter is an easy and secure method to export Check Point logs over syslog. Log Exporter is a multi-threaded daemon service that runs on a log server. Each log that is written on the log server is read by the Log Exporter daemon. It is then transformed into the applicable format and mapping and sent to the end target.

Steps of configuration

To export logs from Harmony Endpoint:

Log in to the console using admin rights

1-Go to Endpoint Settings > Export Events.

2-Click Add.

3-The New Logging Service window opens.

4-Fill in the export details:

  • Name - Enter a name for the exported information.

  • IP Address - Enter the IP Address of the CCE

  • Protocol - UDP.

  • Format - Select the CEF format

  • Port - 514

4-Click Add.

Verification with Using UI

STEP 1:Log in to UI >> SYSTEM

STEP 2: >> Logs and flows collection status

STEP 3: >>To verify the source device IP from the UI:

  • Log in to the user interface

  • Navigate to the "SYSTEM" section

  • Look for the "SOURCE DEVICE IP"

  • Check the IP address that is displayed

  • Compare the IP address displayed against the expected source device IP

This will allow you to ensure that the system is properly identifying the source device IP and that it matches the expected IP address..

Seceon Inc. All rights reserved. https://www.seceon.com