CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-26
Junior Member
 
Join Date: 2006-05-26
Posts: 7
Rep Power: 0
Concrete has an average reputation (10+)
Default Help with Syslogging

Hi There
I have recently started working with CheckPoint FW-1 NG with AI and HFA 14 running on a solaris box.

Anywho here's problem I am trying to get the Checkpoint SmartView log viewer run on a win2k box to also read syslog messages from other products like routers and pix. So far my attempts at solving this have been unsuccesful.

Any Help would be appreciated

Thank You
Reply With Quote
  #2 (permalink)  
Old 2006-06-02
Junior Member
 
Join Date: 2006-05-26
Posts: 7
Rep Power: 0
Concrete has an average reputation (10+)
Default Re: Help with Syslogging

No ideas anyone?

I have found an executable call syslog in the checkpoint folders and have tried that (syslog 514 all).
The executable starts running but it always hangs, and doesn't return to the CLI. So I thought it may need to keep running and I ran it in the background using nice nhup syslog 514 all&.

When I do a ps -ef after running the executable there is a process running and the SmartView Tracker gets a log stating the syslog daemon is running. But doing a netstat and grepping for port 514 shows nothing, so it doesn't seem to be listening and SmartView is not getting any logs from my routers or pix.

Once again I am running Checkpoint NG with AI and HFA 14. It is set up as a management console and I am trying to make it so that SmartView will show all logs instead of having to use 2 programs, one for checkpoint and one for the syslog devices.

Once again ThankYou for you time and help
Concrete
Reply With Quote
  #3 (permalink)  
Old 2006-06-05
Member
 
Join Date: 2005-09-15
Posts: 65
Rep Power: 4
stuartgreen has an average reputation (10+)
Default Re: Help with Syslogging

i'm not sure you can use smartview tracker as a standard syslog server? I think the new release of eventia reporter can import logs from other sources and perform analysis on them. using the check point log server / management server as a single log managment point is not something i've heard of before
Reply With Quote
  #4 (permalink)  
Old 2006-06-05
Junior Member
 
Join Date: 2006-05-26
Posts: 7
Rep Power: 0
Concrete has an average reputation (10+)
Default Re: Help with Syslogging

Darn...I was under the impresstion that there was some form of compatability with syslogs.

http://www.aerasec.de/security/advis...slog-crash.txt
The document lead me to believe that the daemon would allow the logging of syslogs.

As well there is an optiong under aditional logging in the Dashboard program that allows for the recieveing of syslogs. But it doesn't seem to be working any better then the daemon.

O well thanks for your reply, I will start looking into other options starting with this eventia reporter.

Thank You
Concrete
Reply With Quote
  #5 (permalink)  
Old 2006-08-09
Member
 
Join Date: 2006-02-05
Posts: 74
Rep Power: 3
jmcgrady has an average reputation (10+)
Default Re: Help with Syslogging

I have a pix logging to my smartcentre. The entries appear. But they are not parsed. They're just a blank entry except for date, time, origin, and type (log). If i drill into the 'log' field i can see the syslog entry as one big text spiel. Is it possible for Smartcentre to parse syslog entries more intelligently?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:47.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0