<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunking Checkpoint firewall audit log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12590#M960</link>
    <description>&lt;P&gt;Hello,
Is there a way I can configure the lea-loggrabber-splunk to collect Checkpoint's audit log(audit.log), instead of the default collection on traffic log(fw1.log)?
I am using the lea-loggrabber-splunk downloaded from &lt;A href="http://www.splunk.com/wiki/Apps:Configure_OPSEC_LEA_input" rel="nofollow"&gt;http://www.splunk.com/wiki/Apps:Configure_OPSEC_LEA_input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, I noticed that the Offline Mode was used as the collection method. Was there a reason why the Offline Mode was preferred over the Online Mode?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2010 01:02:09 GMT</pubDate>
    <dc:creator>alextsui</dc:creator>
    <dc:date>2010-04-30T01:02:09Z</dc:date>
    <item>
      <title>Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12590#M960</link>
      <description>&lt;P&gt;Hello,
Is there a way I can configure the lea-loggrabber-splunk to collect Checkpoint's audit log(audit.log), instead of the default collection on traffic log(fw1.log)?
I am using the lea-loggrabber-splunk downloaded from &lt;A href="http://www.splunk.com/wiki/Apps:Configure_OPSEC_LEA_input" rel="nofollow"&gt;http://www.splunk.com/wiki/Apps:Configure_OPSEC_LEA_input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, I noticed that the Offline Mode was used as the collection method. Was there a reason why the Offline Mode was preferred over the Online Mode?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2010 01:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12590#M960</guid>
      <dc:creator>alextsui</dc:creator>
      <dc:date>2010-04-30T01:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12591#M961</link>
      <description>&lt;P&gt;haven't had any luck getting the splunk lea_loggrabber to retrieve audit logs, but was able to get it using the FW1-loggrabber binary&lt;/P&gt;

&lt;P&gt;&lt;A href="http://sourceforge.net/projects/fw1-loggrabber"&gt;http://sourceforge.net/projects/fw1-loggrabber&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;FW1-Loggrabber&amp;gt;fw ver
This is Check Point VPN-1(TM) &amp;amp; FireWall-1(R) R75 - Build 254

    [root@localhost etc]# ../bin/fw1-loggrabber
    loc=151|time=2011-06-21 15:57:49|action=accept|orig=172.16.12.202|i/f_dir=outbound|i/f_name=|has_accounting=0|uuid=&amp;lt;00000000,00000000,00000000,00000000&amp;gt;|product=SmartDashboard|Operation=Log Out|Administrator=admin|Machine=WIN-BVJQ2GHXBVN|Subject=Administrator Login|Operation Number=12
[root@localhost etc]# grep audit fw1-loggrabber.conf
FW1_LOGFILE="audit.log"
# FW1_MODE=&amp;lt;audit|normal&amp;gt;
FW1_MODE="audit"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Jun 2011 23:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12591#M961</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2011-06-21T23:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12592#M962</link>
      <description>&lt;P&gt;Can you share more details about how you are running the fw1-loggrabber binary?  I am trying to use the latest version 1.11.1 on linux&lt;BR /&gt;
i am getting errors about illegal entries in fw1-loggrabber.conf file&lt;BR /&gt;
WARNING: Illegal entry in configuration file: FW1_MODE=audit"&lt;/P&gt;

&lt;P&gt;the only entries that dont cause error messages are:&lt;BR /&gt;
DEBUG_LEVEL="3"&lt;BR /&gt;
FW1_LOGFILE="audit.log"&lt;BR /&gt;
RECORD_SEPARATOR="|"&lt;/P&gt;

&lt;P&gt;the rest have to be set via command line:&lt;BR /&gt;
./fw1-loggrabber --resolve --showlogs (the lea.conf and fw1-loggrabber.conf are in local directory)&lt;BR /&gt;
looking forward to your answers&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:42:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12592#M962</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2020-09-28T09:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12593#M963</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[root@localhost default]# cat /opt/splunk/etc/apps/fw1-loggrabber/bin/fw1-loggrabber.sh; /opt/splunk/etc/apps/fw1-loggrabber/bin/fw1-loggrabber.sh |head -n 1; cat /opt/splunk/etc/apps/fw1-loggrabber/default/fw1-loggrabber.conf
#!/bin/bash

cd /opt/splunk/etc/apps/fw1-loggrabber/bin
./fw1-loggrabber -l /opt/splunk/etc/apps/fw1-loggrabber/default/lea.conf -c /opt/splunk/etc/apps/fw1-loggrabber/default/fw1-loggrabber.conf
loc=0|time=1308349341|action=accept|orig=172.16.12.202|i/f_dir=outbound|i/f_name=|has_accounting=0|uuid=&amp;lt;00000000,00000000,00000000,00000000&amp;gt;|product=FWM|ObjectName=WIN-BVJQ2GHXBVN|ObjectType=gateway_ckp|ObjectTable=network_objects|Operation=Create Object|Uid={7E101A87-F44F-4D4B-B34E-41A2F38B8768}|Administrator=Security Management Server|Machine=localhost|Subject=Object Manipulation|Operation Number=0|FieldsChanges=IP Address: '172.16.12.202'; 
# DEBUG_LEVEL=&amp;lt;debuglevel&amp;gt;
DEBUG_LEVEL="0"

#
# FW1 configuration settings
#
# FW1_LOGFILE=&amp;lt;Name of FW1-Logfilename&amp;gt;
FW1_LOGFILE="audit.log"

# FW1_OUTPUT=&amp;lt;files|logs&amp;gt;
FW1_OUTPUT="logs"

# FW1_TYPE=&amp;lt;ng|2000&amp;gt;
FW1_TYPE="ng"

# FW1_MODE=&amp;lt;audit|normal&amp;gt;
FW1_MODE="audit"

# ONLINE_MODE=&amp;lt;yes|no&amp;gt;
ONLINE_MODE="no"

# RESOLVE_MODE=&amp;lt;yes|no&amp;gt;
RESOLVE_MODE="no"

# SHOW_FIELDNAMES=&amp;lt;yes|no&amp;gt;
SHOW_FIELDNAMES="yes"

# RECORD_SEPARATOR=&amp;lt;char&amp;gt;
RECORD_SEPARATOR="|"

# DATEFORMAT=&amp;lt;cp|unix|std&amp;gt;
#   cp   = " 3Feb2004 14:15:16"
#   unix = "1051655431"
#   std  = "2004-02-03 14:15:16"
DATEFORMAT="unix"

# LOGGING_CONFIGURATION=&amp;lt;screen|file|syslog|odbc&amp;gt;
# syslog mode is only Unix like Operating Systems, such as Linux, Solaris
LOGGING_CONFIGURATION=screen

# OUTPUT_FILE_PREFIX=&amp;lt;Path and Name of outputfile&amp;gt;
OUTPUT_FILE_PREFIX="fw1-loggrabber"

# OUTPUT_FILE_ROTATESIZE=&amp;lt;maximum size of outputfile in bytes&amp;gt;
OUTPUT_FILE_ROTATESIZE=1048576

# SYSLOG_FACILITY=&amp;lt;USER|LOCAL0|...|LOCAL7&amp;gt;
SYSLOG_FACILITY="LOCAL1"

# ODBC_DSN=&amp;lt;dsn&amp;gt;
#ODBC_DSN=FW1-LOGGRABBER

# FW1_FILTER_RULE=&amp;lt;rule&amp;gt;
#FW1_FILTER_RULE="action=drop"

# AUDIT_FILTER_RULE=&amp;lt;rule&amp;gt;
#AUDIT_FILTER_RULE="action=accept"

# FIELDS=&amp;lt;field1;field2;...&amp;gt;
#FIELDS=loc;src;dst

[root@localhost default]# 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;is that a possible typo in your configuration file?&lt;BR /&gt;
One awesome feature is the ability to pass options instead to troubleshoot.&lt;/P&gt;

&lt;P&gt;[root@localhost default]# /opt/splunk/etc/apps/fw1-loggrabber/bin/fw1-loggrabber --help&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;FW1-Loggrabber v1.11.1 (no ODBC-support)
    (C)2005, Torsten Fellhauer, Xiaodong Lin

Usage:
 /opt/splunk/etc/apps/fw1-loggrabber/bin/fw1-loggrabber [ options ]
  -c|--configfile &amp;lt;file&amp;gt;     : Name of Configfile (default: fw1-loggrabber.conf)
  -l|--leaconfigfile &amp;lt;file&amp;gt;  : Name of Leaconfigfile (default: lea.conf)
  -f|--logfile Logfile|ALL   : Name of Logfile (default: fw.log)
  --resolve|--no-resolve     : Resolve Port Numbers and IP-Addresses (Default: Resolve)
  --showfiles|--showlogs     : Show only Filenames of all available FW-1 Logfiles (default: showlogs)
  --2000|--ng                : Connect to a CP FW-1 4.1 (2000) (default is ng)
  --filter "..."             : Specify filters to be applied
  --fields "..."             : Specify fields to be printed
  --online|--no-online       : Enable Online mode (default: no-online)
  --auditlog|--normallog     : Get data of audit-logfile (fw.adtlog)(default: normallog)
  --fieldnames|--nofieldnames: Print fieldnames in each line or once at beginning
  --debug-level &amp;lt;level&amp;gt;      : Specify Debuglevel (default: 0 - no debugging)
  --help                     : Show usage informations
  --help-fields              : Show supported log fields
[root@localhost default]# 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Jun 2011 16:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12593#M963</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2011-06-23T16:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12594#M964</link>
      <description>&lt;P&gt;Thanks, I have the same version:&lt;BR /&gt;
FW1-Loggrabber v1.11.1 (no ODBC-support)&lt;BR /&gt;
    (C)2005, Torsten Fellhauer, Xiaodong Lin&lt;BR /&gt;
and have had to use the command line method of specifying the options as the config file keeps mentioning invalid options.&lt;BR /&gt;
Have you used this binary for the fw.log files as well?&lt;BR /&gt;
do you use this binary in online or offline mode to get the audit log items?&lt;BR /&gt;
how do you ensure that you dont get dupliate events in splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2011 17:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12594#M964</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2011-06-23T17:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking Checkpoint firewall audit log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12595#M965</link>
      <description>&lt;P&gt;Could your typo be a missing quotation mark between the equals sign and the lowercase letter "a"?  &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;FW1_MODE=audit"&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2011 13:19:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunking-Checkpoint-firewall-audit-log/m-p/12595#M965</guid>
      <dc:creator>spencers</dc:creator>
      <dc:date>2011-11-01T13:19:47Z</dc:date>
    </item>
  </channel>
</rss>

