<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App for Check Point in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279922#M53573</link>
    <description>&lt;P&gt;I am currently pulling logs from my Check Point Management station successfully and can search on them with no issues. I am trying to get the Splunk app for Check Point to display data and am looking for some clarification on what indexes need to be created? &lt;/P&gt;

&lt;P&gt;Currently I have all Check Point non-audit logs going into the default index. Can anyone clarify for me what index the Splunk App for Check Point looks at and what index or indexes I need to create?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 13:37:36 GMT</pubDate>
    <dc:creator>gstefancyk</dc:creator>
    <dc:date>2016-10-25T13:37:36Z</dc:date>
    <item>
      <title>Splunk App for Check Point</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279922#M53573</link>
      <description>&lt;P&gt;I am currently pulling logs from my Check Point Management station successfully and can search on them with no issues. I am trying to get the Splunk app for Check Point to display data and am looking for some clarification on what indexes need to be created? &lt;/P&gt;

&lt;P&gt;Currently I have all Check Point non-audit logs going into the default index. Can anyone clarify for me what index the Splunk App for Check Point looks at and what index or indexes I need to create?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 13:37:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279922#M53573</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2016-10-25T13:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Check Point</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279923#M53574</link>
      <description>&lt;P&gt;The Splunk app for Checkpoint seems to use &lt;CODE&gt;checkpoint_index&lt;/CODE&gt;as a macro behind most of the searches.  That macro is simple and says &lt;CODE&gt;index=checkpoint&lt;/CODE&gt;, so your data needs to be indexed in the index "checkpoint".  (You could - though I don't recommend it - change that macro to point to main.  More explanation can be given, but mostly it's just you shouldn't use main.)&lt;/P&gt;

&lt;P&gt;Speaking of which, did you set up the &lt;A href="https://splunkbase.splunk.com/app/3197/"&gt;Splunk add-on for Check Point OPSEC LEA&lt;/A&gt; as the &lt;A href="https://splunkbase.splunk.com/app/2670/#/details"&gt;docs mention&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 13:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279923#M53574</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-10-25T13:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Check Point</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279924#M53575</link>
      <description>&lt;P&gt;Thanks rich7177. &lt;/P&gt;

&lt;P&gt;I must have missed that little section at the bottom of the App details page that says log everything to "checkpoint". I have configured the opsec lea add on to log to index checkpoint and data is now populating the Splunk App for Check Point.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 14:15:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-App-for-Check-Point/m-p/279924#M53575</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2016-10-25T14:15:43Z</dc:date>
    </item>
  </channel>
</rss>

