gvaltas

Captain
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2021-02-22
10:18
106 views
ArcSight - Integration with Checkpoint Sandblast Agent Logs
Hi all,
Have ever anyone integrated Sandblast agent alert logs (EDR solution from CheckPoint) with ArcSight?
In the following link: https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SandBlast-Agent-Admin-Guide/Topics-SBA-AG/Log-Exporter.htm?TocPath=_____19
it is mentioned that Log Exporter can be used for log extraction and sent to remote syslog server using CEF format.
I have tested the Log Exporter for the rest of the Checkpoint Logs (Log Exporter CEF/Management Console) but not the Sandblast agent logs.
Thank you,
Greg
0 Replies