I am running Checkpoint R77.20 (a cluster of 4 firewalls running on Secure Platform and a separate firewall management server running on Windows server 2008R2)
I have been asked to forward some of the firewall traffic logs to an SIEM Event Collector (which is not controlled by me). However I can't send ALL of the firewall logs as some traffic is confidential. I'm therefore looking for a way of sending a selection of firewall traffic logs to the SIEM server. (Also I want to retain the logs on my management server so that I'm still able to view them myself).
As I understand it the options are:
a) Set up an LEA server on the firewall management server and allow the LEA client on the SIEM server to connect to the firewall management server to get the firewall traffic logs.
b) forward the traffic logs from the firewall management server to a syslog server using OPSEC.
c) send the firewall logs directly from the firewalls (not from the management server) by setting up user defined logging rules and then configuring a script to send the logs to the syslog server.
I was wondering if anyone could advise me of the best solution? Many thanks