<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunking Check Point logs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41311#M69918</link>
    <description>&lt;P&gt;Thanks a lot MarioM. &lt;/P&gt;

&lt;P&gt;The link was very helpful. &lt;BR /&gt;
Was able to see the problem with debug. &lt;BR /&gt;
opsec_entity_sic_name was set wrongly. &lt;BR /&gt;
Able to see the Checkpoint logs now.&lt;/P&gt;

&lt;P&gt;You are a great help.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:46:13 GMT</pubDate>
    <dc:creator>alvin</dc:creator>
    <dc:date>2020-09-28T11:46:13Z</dc:date>
    <item>
      <title>Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41305#M69912</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am trying to get logs from Check Point Firewall into our Splunk server.&lt;/P&gt;

&lt;P&gt;We have a cluster of 2 UTM-1 Firewalls managed by a Smart-1.&lt;/P&gt;

&lt;P&gt;Firewall Logs are being sent to the Smart-1.&lt;/P&gt;

&lt;P&gt;All Checkpoint are running R75.20.&lt;/P&gt;

&lt;P&gt;I have configured Splunk OPSEC LEA-Loggrabber to connect to the Smart-1 to grab the logs according to the guide from &lt;A href="http://splunk-base.splunk.com/apps/22386/opsec-lea-for-check-point-linux"&gt;http://splunk-base.splunk.com/apps/22386/opsec-lea-for-check-point-linux&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Everything seems well except i do not see any data with sourcetype=opsec on Splunk.&lt;/P&gt;

&lt;P&gt;Will anyone be able to assist with my set up?&lt;/P&gt;

&lt;P&gt;I will be glad to provide more info.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Alvin&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2012 09:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41305#M69912</guid>
      <dc:creator>alvin</dc:creator>
      <dc:date>2012-05-02T09:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41306#M69913</link>
      <description>&lt;P&gt;what do you see in internal logs?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd "lea-loggrabber.sh"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 May 2012 09:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41306#M69913</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-02T09:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41307#M69914</link>
      <description>&lt;P&gt;internal logs results:&lt;/P&gt;

&lt;P&gt;05-02-2012 18:21:28.762 +0800 INFO  ExecProcessor - Ran script: /opt/splunk/etc/apps/lea-loggrabber-splunk/bin/lea-loggrabber.sh, took 317.9 milliseconds to run, 0 bytes read&lt;/P&gt;

&lt;P&gt;Occurs every minute.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2012 10:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41307#M69914</guid>
      <dc:creator>alvin</dc:creator>
      <dc:date>2012-05-02T10:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41308#M69915</link>
      <description>&lt;P&gt;do you send it to a specific index or default one ?&lt;/P&gt;

&lt;P&gt;do you get anything from this search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* source="*lea-loggrabber*"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 May 2012 10:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41308#M69915</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-02T10:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41309#M69916</link>
      <description>&lt;P&gt;default index.&lt;BR /&gt;
Got nothing from the above search.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2012 10:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41309#M69916</guid>
      <dc:creator>alvin</dc:creator>
      <dc:date>2012-05-02T10:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41310#M69917</link>
      <description>&lt;P&gt;then your Smart-1 are possibly not sending data...&lt;BR /&gt;
You need to do packet capture to see if any data from your smart-1 is reaching the splunk machine.&lt;BR /&gt;
As well you could try lea debug as per this answer:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/33875/how-can-i-debug-my-lea-client-for-checkpoint"&gt;http://splunk-base.splunk.com/answers/33875/how-can-i-debug-my-lea-client-for-checkpoint&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2012 11:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41310#M69917</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-02T11:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41311#M69918</link>
      <description>&lt;P&gt;Thanks a lot MarioM. &lt;/P&gt;

&lt;P&gt;The link was very helpful. &lt;BR /&gt;
Was able to see the problem with debug. &lt;BR /&gt;
opsec_entity_sic_name was set wrongly. &lt;BR /&gt;
Able to see the Checkpoint logs now.&lt;/P&gt;

&lt;P&gt;You are a great help.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41311#M69918</guid>
      <dc:creator>alvin</dc:creator>
      <dc:date>2020-09-28T11:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Check Point logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41312#M69919</link>
      <description>&lt;P&gt;I'd just like to add that I too had a problem identifying the correct value for opsec_entity_sic. Getting the SIC DN from the GUI isn't obvious to me in R75.30. I found this command which can be run from the expert shell on the management server which provides a list of values including the DN for your management server.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cpca_client lscert -kind SIC
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunking-Check-Point-logs/m-p/41312#M69919</guid>
      <dc:creator>PunchMonkey</dc:creator>
      <dc:date>2020-09-28T11:50:40Z</dc:date>
    </item>
  </channel>
</rss>

