<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I use Splunk to retrieve my CheckPoint Firewall Rules? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-can-I-use-Splunk-to-retrieve-my-CheckPoint-Firewall-Rules/m-p/141666#M4338</link>
    <description>&lt;P&gt;You will need a Heavy Forwarder with the Splunk Add-on For OPSEC LEA: &lt;A href="http://docs.splunk.com/Documentation/OPSEC-LEA"&gt;http://docs.splunk.com/Documentation/OPSEC-LEA&lt;/A&gt;.  It really all depends on how your CheckPoint Environment is setup.  The Add-On use LEA-Logger to pull the logs via a rest call in to a Heavy Forwarder were they are unpackaged, transformed and sent to an indexer.&lt;/P&gt;

&lt;P&gt;You have to use a Heavy Forwarder so you can configure it over the GUI.  Once it's configured you're good to go. &lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2015 14:19:17 GMT</pubDate>
    <dc:creator>mgonter_splunk</dc:creator>
    <dc:date>2015-06-04T14:19:17Z</dc:date>
    <item>
      <title>How can I use Splunk to retrieve my CheckPoint Firewall Rules?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-use-Splunk-to-retrieve-my-CheckPoint-Firewall-Rules/m-p/141665#M4337</link>
      <description>&lt;P&gt;How can I use Splunk to retrieve my CheckPoint Firewall Rules&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 22:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-use-Splunk-to-retrieve-my-CheckPoint-Firewall-Rules/m-p/141665#M4337</guid>
      <dc:creator>JeanC</dc:creator>
      <dc:date>2014-07-14T22:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use Splunk to retrieve my CheckPoint Firewall Rules?</title>
      <link>https://community.splunk.com/t5/Security/How-can-I-use-Splunk-to-retrieve-my-CheckPoint-Firewall-Rules/m-p/141666#M4338</link>
      <description>&lt;P&gt;You will need a Heavy Forwarder with the Splunk Add-on For OPSEC LEA: &lt;A href="http://docs.splunk.com/Documentation/OPSEC-LEA"&gt;http://docs.splunk.com/Documentation/OPSEC-LEA&lt;/A&gt;.  It really all depends on how your CheckPoint Environment is setup.  The Add-On use LEA-Logger to pull the logs via a rest call in to a Heavy Forwarder were they are unpackaged, transformed and sent to an indexer.&lt;/P&gt;

&lt;P&gt;You have to use a Heavy Forwarder so you can configure it over the GUI.  Once it's configured you're good to go. &lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 14:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-can-I-use-Splunk-to-retrieve-my-CheckPoint-Firewall-Rules/m-p/141666#M4338</guid>
      <dc:creator>mgonter_splunk</dc:creator>
      <dc:date>2015-06-04T14:19:17Z</dc:date>
    </item>
  </channel>
</rss>

