CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-06-26
Junior Member
 
Join Date: 2008-08-27
Location: California
Posts: 4
Rep Power: 0
gregrack has an average reputation (10+)
Default Eventia (R70) Log Parsing Editor

Has anyone out there used the Eventia Log Parsing Editor with R70? I understand it is suppose to help CP (Eventia/Tracker(?)) better understand syslogs sent to it. Rather than re-invent the wheel, I had hoped to find a standard PRS file somewhere online with the basic Cisco, etc, syslogs defined already. I'm actually surprised by how few of the syslogs match by default...

Has anyone used this tool?

Last edited by gregrack; 2009-06-26 at 12:14.
Reply With Quote
  #2 (permalink)  
Old 2009-06-29
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 2,344
Rep Power: 7
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Eventia (R70) Log Parsing Editor

From my experience it is being mostly used to process CP logs.
With the new pricing structure (Match EVA to the size of the SmartCenter), processing other devices is a lot more economical. Hopefully that will spur more syslog usage & development.

Maybe Barry could set up a section where we could publish PRS files that we want to share.

Last edited by chillyjim; 2009-06-29 at 05:45.
Reply With Quote
  #3 (permalink)  
Old 2009-06-29
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 892
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Eventia (R70) Log Parsing Editor

Quote:
Originally Posted by chillyjim View Post
From my experience it is being mostly used to process CP logs.
With the new pricing structure (Match EVA to the size of the SmartCenter), processing other devices is a lot more economical. Hopefully that will spur more syslog usage & development.

Maybe Barry could set up a section where we could publish PRS files that we want to share.
Start off by posting them in this thread; if we need to, we'll move them all to a new thread.
__________________
Barry J. Stiefel ("Stee-ful")
B.S., MBA, CCSA/CCSE/CCSE+/CCSI
Resilience RCSE/RCSI, Fortinet FCSE
CISSP, MCSE, NSA ISM
President, CPUG, CPUG University, CPUG CON
Reply With Quote
  #4 (permalink)  
Old 2009-10-02
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 1,056
Rep Power: 5
RayPesek has an average reputation (10+)
Default Re: Eventia (R70) Log Parsing Editor

Quote:
Originally Posted by chillyjim View Post
With the new pricing structure (Match EVA to the size of the SmartCenter), processing other devices is a lot more economical.
The new pricing structure where only CP firewalls need a licenses, rather than having to license everything sending to Eventia, has me baffled regarding the size of the SmartCenter.

We've got an unlimited SmartCenter on R65 and will go to an unlimited on blades as well. But we've got less than ten firewalls. If we license EVA to the unlimited SmartCenter, it costs me $32,000. But if I buy an extra "little" SmartCenter license, I can have EVA/ER for $8,000 + the $4,000 SmartCenter license.

Sure seems stupid to me. Just count the number of firewalls I have and don't make me play these dumb games.

Ray
Reply With Quote
  #5 (permalink)  
Old 2009-10-02
Senior Member
 
Join Date: 2005-08-14
Location: Gig Harbor, WA, USA
Posts: 622
Rep Power: 5
PhoneBoy has an average reputation (10+)
Default Re: Eventia (R70) Log Parsing Editor

You can have an unlimited SmartCenter, but have an Eventia license for less than unlimited gateways. What matters as far as Eventia is concerned is the ACTUAL number of gateways you manage. So no, you don't need to buy an unlimited Eventia license. :)
Reply With Quote
  #6 (permalink)  
Old 2009-10-02
Senior Member
 
Join Date: 2007-07-16
Posts: 1,873
Rep Power: 4
Thorpuse has an average reputation (10+)
Default Re: Eventia (R70) Log Parsing Editor

Quote:
Originally Posted by RayPesek View Post

Sure seems stupid to me. Just count the number of firewalls I have and don't make me play these dumb games.
This is one of those classic cases where for some customers, the pricing changes dramatically in their favour, and for others, it goes the other way. Personally, I prefer the tying to management size, because working out device counts per device with the old system beame really expensive, really quickly once you added non-CP devices to the mix. This is one of the few cases where SW blades actually can bring an ecomonic benefit to a customer compared to the old pricelist.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:57.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2