Use https://seceonhelp.freshdesk.com/support/login to access updated Knowledge Base Articles, Submit Technical Support Tickets and Review Status of submitted support tickets.
Checkpoint Harmony Exporting Logs
Overview
Check Point Log Exporter is an easy and secure method to export Check Point logs over syslog. Log Exporter is a multi-threaded daemon service that runs on a log server. Each log that is written on the log server is read by the Log Exporter daemon. It is then transformed into the applicable format and mapping and sent to the end target.
Steps of configuration
To export logs from Harmony Endpoint:
Log in to the console using admin rights
1-Go to Endpoint Settings > Export Events.
2-Click Add.
3-The New Logging Service window opens.
4-Fill in the export details:
Name - Enter a name for the exported information.
IP Address - Enter the IP Address of the CCE
Protocol - UDP.
Format - Select the CEF format
Port - 514
4-Click Add.
Verification with Using UI
STEP 1:Log in to UI >> SYSTEM
STEP 2: >> Logs and flows collection status
STEP 3: >>To verify the source device IP from the UI:
Log in to the user interface
Navigate to the "SYSTEM" section
Look for the "SOURCE DEVICE IP"
Check the IP address that is displayed
Compare the IP address displayed against the expected source device IP
This will allow you to ensure that the system is properly identifying the source device IP and that it matches the expected IP address..
Seceon Inc. All rights reserved. https://www.seceon.com