bcgov / cloud-pathfinder

This is the technology and UX backend repo for the cloud pathfinder ZenHub task board
https://app.zenhub.com/workspaces/cloud-pathfinder-5e4dbb426c3c6af8dcbf06a7/board?repos=241742911
Creative Commons Zero v1.0 Universal
2 stars 8 forks source link

Q4: Send Check Point firewall logs to syslog endpoint #2001

Open wrnu opened 2 years ago

wrnu commented 2 years ago

Describe the issue Configure Check Point firewalls to send logs to SysLog server.

We want to save checkpoint firewall logs and make them available to the OpenSearch SIEM. Check Point does not have a CloudWatch logging agent in the AMI but does support sending logs to a sys log endpoint. The SEA was designed to have an Rsyslog proxy endpoint in the Operations account for this purpose (originally for Fortigate).

Additional context

Definition of done

ActionAnalytics commented 2 years ago

Waiting for capability coming in Q4 that would work instead of us hacking together a wobbly solution

lukegonis commented 1 year ago

@NickCorcoran can you please review this issue and determine if it is still a valuable thing to pursue? We need private link endpoint service to support UDP.