<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk add-on for Check Point OPSEC LEA: Change HOST field to be firewall IP not the management station ip in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374753#M45451</link>
    <description>&lt;P&gt;We have been ingesting our Check Point logs via the Check Point OPSEC LEA add-on and finally realized that the HOST being reported is always our management station IP where we are pulling logs from... Is there a way to change this in the OPSEC Lea add on or would we be better off doing this in transforms.conf and props.conf on the heavy forwarder? &lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2018 17:19:39 GMT</pubDate>
    <dc:creator>gstefancyk</dc:creator>
    <dc:date>2018-02-13T17:19:39Z</dc:date>
    <item>
      <title>Splunk add-on for Check Point OPSEC LEA: Change HOST field to be firewall IP not the management station ip</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374753#M45451</link>
      <description>&lt;P&gt;We have been ingesting our Check Point logs via the Check Point OPSEC LEA add-on and finally realized that the HOST being reported is always our management station IP where we are pulling logs from... Is there a way to change this in the OPSEC Lea add on or would we be better off doing this in transforms.conf and props.conf on the heavy forwarder? &lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 17:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374753#M45451</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2018-02-13T17:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Check Point OPSEC LEA: Change HOST field to be firewall IP not the management station ip</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374754#M45452</link>
      <description>&lt;P&gt;You can use props and transforms to overwrite it (e.g. based on the orig= field).&lt;BR /&gt;
See this recent discussion: &lt;A href="https://answers.splunk.com/answers/615561/how-to-overwrite-the-host-field-value-with-dvc-fie.html"&gt;https://answers.splunk.com/answers/615561/how-to-overwrite-the-host-field-value-with-dvc-fie.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 12:22:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374754#M45452</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-02-28T12:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Check Point OPSEC LEA: Change HOST field to be firewall IP not the management station ip</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374755#M45453</link>
      <description>&lt;P&gt;Thanks FrankVI, exactly what I expected but nice to get some re-assurance. &lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 12:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374755#M45453</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2018-02-28T12:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Check Point OPSEC LEA: Change HOST field to be firewall IP not the management station ip</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374756#M45454</link>
      <description>&lt;P&gt;What field was your fw coming into Splunk as? And did you have to change logging on mgmt server to get the fw info to be sent to Splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-add-on-for-Check-Point-OPSEC-LEA-Change-HOST-field-to-be/m-p/374756#M45454</guid>
      <dc:creator>mathieuamos</dc:creator>
      <dc:date>2018-05-21T18:48:39Z</dc:date>
    </item>
  </channel>
</rss>

