<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint lea_loggrabber enhancement in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65630#M13183</link>
    <description>&lt;P&gt;Some questions for you:&lt;BR /&gt;&lt;BR /&gt;
- On what platform have you attempted to run the modified lea_loggrabber binary?&lt;BR /&gt;&lt;BR /&gt;
- Do you get the "segmentation fault" error with the unmodified binary?&lt;BR /&gt;&lt;BR /&gt;
- What output do you see when running lea_loggrabber from the command line?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:23:21 GMT</pubDate>
    <dc:creator>hexx</dc:creator>
    <dc:date>2020-09-28T11:23:21Z</dc:date>
    <item>
      <title>CheckPoint lea_loggrabber enhancement</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65626#M13179</link>
      <description>&lt;P&gt;The CheckPoint LEA Application  (lea_loggrabber) seems to be grabbing every field that appears in the logs without putting a delimeter between the fields.  In most cases this is ok but there are several fields (ex attack and Attack Info) that are not easy to parse out.  Extracting values can easily get values that contains the next field name.&lt;/P&gt;

&lt;P&gt;Example Data: (field names on bold)&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Industry Reference&lt;/STRONG&gt;=CVE-2008-2469 Protection Type=protection &lt;STRONG&gt;Attack Info&lt;/STRONG&gt;=DNS TXT record parsing buffer overflow &lt;STRONG&gt;attack&lt;/STRONG&gt;=DNS Enforcement Violation &lt;STRONG&gt;SmartDefense profile&lt;/STRONG&gt;=Default_Protection_NO_NetQ&lt;/P&gt;

&lt;P&gt;In this case if you extracted the attack field you might get "DNS Enforcement Violation SmartDefense" instead of the expected "DNS Enforcement Violation".&lt;/P&gt;

&lt;P&gt;One solution would be to put a known delimeter such as | between the fields.  I know this was an option with the fw1-loggrabber application but it has been stated that this program has stability issues.&lt;/P&gt;

&lt;P&gt;So can you please add an option to the lea_loggrabber application to optionally add a delimeter between the grabbed fields. Or provide the sourcecode for the lea_loggrabber application so this can be done?&lt;/P&gt;

&lt;P&gt;lea_loggrabber output would be better if like this:&lt;/P&gt;

&lt;P&gt;|&lt;STRONG&gt;Industry Reference&lt;/STRONG&gt;=CVE-2008-2469 |Protection Type=protection |&lt;STRONG&gt;Attack Info&lt;/STRONG&gt;=DNS TXT record parsing buffer overflow |&lt;STRONG&gt;attack&lt;/STRONG&gt;=DNS Enforcement Violation |&lt;STRONG&gt;SmartDefense profile&lt;/STRONG&gt;=Default_Protection_NO_NetQ&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2010 02:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65626#M13179</guid>
      <dc:creator>KGolomb</dc:creator>
      <dc:date>2010-10-07T02:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint lea_loggrabber enhancement</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65627#M13180</link>
      <description>&lt;P&gt;I agree completely, the ability to define (or have a standard delimeter) for fw1-loggrabber is a bonus.&lt;/P&gt;

&lt;P&gt;Other features that would be required, getting the audit.log file&lt;BR /&gt;
more debug information as available in fw1-loggrabber for troubleshooting SIC issues.&lt;BR /&gt;
the ability to resolve or not resolve the ip addresses and services so that we can get either the raw IP addresses/port numbers or the object names and service names.  This would make it easier to cross reference the ip's with other firewall types that offer this ability.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 17:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65627#M13180</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2011-06-23T17:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint lea_loggrabber enhancement</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65628#M13181</link>
      <description>&lt;P&gt;With the contribution of Splunk Answers user &lt;A href="http://splunk-base.splunk.com/users/168/treyka" target="_blank"&gt;treyka&lt;/A&gt;, we we were able to patch and recompile the "lea_loggrabber" Linux binary to outputs semi-colons as delimiters between field/value pairs :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Before :&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;loc=2445861 filename=fw.log fileid=1314230340 time=25Aug2011 12:40:58 action=drop orig=FIREWALLNAME i/f_dir=inbound i/f_name=eth-s2p2c0 has_accounting=0 product=VPN-1 &amp;amp; FireWall-1 __policy_id_tag=product=VPN-1 &amp;amp; FireWall-1[db_tag={AAAAAAA-BBBBB-CCCCCC-DDDDDDD-EEEEEEEEEE};mgmt=LAB-CMA;date=1310743754;policy_name=ABCD_Policy] rule=77 rule_uid={19AD44C1-79E0-422F-91A6-FF2E6A818EEE} SmartDefense profile=No Protection src=1.2.3.4 s_port=40552 dst=4.3.2.1service=snmp-read proto=udp&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;After :&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;time=26Aug2011 12:34:34;action=drop;fw=1.2.3.4;if_dir=inbound;if_name=eth-s2p2c0;mgmt=LAB-CMA;policy_name=ABCD_Policy;rule=77;src=1.2.3.4;s_port=11334;dst=4.3.2.1;d_port=161;proto=udp;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;In addition, this patched version of "lea_loggrabber" accepts new, mutually exclusive parameters to control the name resolution of objects :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The option "&lt;CODE&gt;--resolve&lt;/CODE&gt;" will cause objects to be resolved, as is currently the case. Example :&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;time= 4Aug2011 22:47:52;action=accept;fw=Win2k3-86sup01;if_dir=inbound;if_name=E1G606;mgmt=Win2k3-86sup01;policy_name=Standard;rule=2;rule_name=LEA traffic;service_id=FW1_lea;src=beefysup01.splunk.com;s_port=33776;dst=Win2k3-86sup01;d_port=FW1_lea;proto=tcp;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The option "&lt;CODE&gt;--no-resolve&lt;/CODE&gt;" will prevent object name resolution. Example :&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;time= 4Aug2011 22:47:00;action=accept;fw=10.160.31.56;if_dir=inbound;if_name=E1G606;mgmt=Win2k3-86sup01;policy_name=Standard;rule=2;rule_name=LEA traffic;service_id=FW1_lea;src=10.1.12.1;s_port=47250;dst=10.160.31.56;d_port=18184;proto=tcp;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;Some important remarks :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;This patched version of the lea_loggrabber binary is not currently integrated to the app packaged on splunkbase. It can be obtained by requesting it from Splunk Support. Please &lt;A href="http://www.splunk.com/index.php/submit_issue" target="_blank"&gt;open a support case&lt;/A&gt; if you would like to receive it.&lt;/LI&gt;
&lt;LI&gt;Only the Linux (32bit/64bit) version of the lea_loggrabber binary has been recompiled with this patch.&lt;/LI&gt;
&lt;LI&gt;The patched binary will be provided "as is". It has not been tested by Splunk Quality Assurance, which is why it has not yet been integrated in the package available on splunkbase.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65628#M13181</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2020-09-28T09:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint lea_loggrabber enhancement</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65629#M13182</link>
      <description>&lt;P&gt;My customer using try this and got error message saying that "Segmentation fault". Any suggestion?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2012 19:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65629#M13182</guid>
      <dc:creator>ksirisawatdi_sp</dc:creator>
      <dc:date>2012-02-10T19:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint lea_loggrabber enhancement</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65630#M13183</link>
      <description>&lt;P&gt;Some questions for you:&lt;BR /&gt;&lt;BR /&gt;
- On what platform have you attempted to run the modified lea_loggrabber binary?&lt;BR /&gt;&lt;BR /&gt;
- Do you get the "segmentation fault" error with the unmodified binary?&lt;BR /&gt;&lt;BR /&gt;
- What output do you see when running lea_loggrabber from the command line?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CheckPoint-lea-loggrabber-enhancement/m-p/65630#M13183</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2020-09-28T11:23:21Z</dc:date>
    </item>
  </channel>
</rss>

