<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint with Splunk on Windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71975#M14689</link>
    <description>&lt;P&gt;Hi all, &lt;BR /&gt;
loggrabber works fine, but I can't make it work correctly with splunk. &lt;/P&gt;

&lt;P&gt;Did anyone already manage to fetch logs vialea on windows splunk ? &lt;/P&gt;

&lt;P&gt;thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2012 09:21:13 GMT</pubDate>
    <dc:creator>nicolasfigaro</dc:creator>
    <dc:date>2012-07-02T09:21:13Z</dc:date>
    <item>
      <title>Checkpoint with Splunk on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71973#M14687</link>
      <description>&lt;P&gt;Does the Checkpoint LEA app work on windows?  or has anyone tweaked it to work?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2010 21:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71973#M14687</guid>
      <dc:creator>Michael_Wilde</dc:creator>
      <dc:date>2010-10-18T21:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint with Splunk on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71974#M14688</link>
      <description>&lt;P&gt;just tested the Windows FW1-loggrabber executable (1.11.1) and it works well with R75. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://sourceforge.net/projects/fw1-loggrabber/"&gt;http://sourceforge.net/projects/fw1-loggrabber/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I'm sure the splunk APP can be tweaked to accommodate the event data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\set4bits\FW1-Loggrabber&amp;gt;fw ver
This is Check Point VPN-1(TM) &amp;amp; FireWall-1(R) R75 - Build 254
C:\set4bits\FW1-Loggrabber&amp;gt;fw1-loggrabber.exe |more
loc=0|time=2011-06-17 17:51:38|action=ctl|orig=172.16.12.200|i/f_dir=inbound|i/f
_name=daemon|has_accounting=0|uuid=&amp;lt;00000000,00000000,00000000,00000000&amp;gt;|log_sys
_message=Log file has been switched to: 2011-06-17_152203_1.log
loc=1|time=2011-06-17 17:51:43|action=accept|orig=172.16.12.200|i/f_dir=inbound|
i/f_name=E1G606|has_accounting=0|uuid=&amp;lt;4dfbf69f,00000000,c80c10ac,0000ffff&amp;gt;|prod
uct=VPN-1 &amp;amp; FireWall-1|__policy_id_tag=product=VPN-1 &amp;amp; FireWall-1[db_tag={9D0262
9E-B095-40D3-AE39-FA4DA8BB5F01};mgmt=WIN-BVJQ2GHXBVN;date=1308353659;policy_name
=Standard]|src=172.16.12.138|s_port=60819|dst=172.16.12.200|service=18184|proto=
tcp|rule=4
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Jun 2011 22:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71974#M14688</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2011-06-21T22:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint with Splunk on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71975#M14689</link>
      <description>&lt;P&gt;Hi all, &lt;BR /&gt;
loggrabber works fine, but I can't make it work correctly with splunk. &lt;/P&gt;

&lt;P&gt;Did anyone already manage to fetch logs vialea on windows splunk ? &lt;/P&gt;

&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2012 09:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Checkpoint-with-Splunk-on-Windows/m-p/71975#M14689</guid>
      <dc:creator>nicolasfigaro</dc:creator>
      <dc:date>2012-07-02T09:21:13Z</dc:date>
    </item>
  </channel>
</rss>

