<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: trouble with checkpoint logs in Installation</title>
    <link>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749699#M14411</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;livehybrid :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ty , i try to change the default template for this&amp;nbsp;&amp;nbsp;Template="RSYSLOG_SyslogProtocol23Format" and now it works !!!! Ty for thew help&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2025 07:59:35 GMT</pubDate>
    <dc:creator>josevg1981</dc:creator>
    <dc:date>2025-07-14T07:59:35Z</dc:date>
    <item>
      <title>trouble with checkpoint logs</title>
      <link>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749623#M14409</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have the following setup:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Check Point Firewall is configured to send logs via syslog over UDP (port 514).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Logs are received by a Linux server running rsyslog.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;rsyslog writes these logs to a local file (e.g., /var/log/CheckPoint.log).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Splunk (on the same server) reads this file and indexes the logs&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Although the Check Point firewall sends complete logs (visible in tcpdump, including structured data and original timestamps), only a truncated version of the log is written to the file by rsyslog. Specifically:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The structured message body is missing.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Only the syslog header (timestamp, hostname, program name) appears in the file.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Can anyonehelp !!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ty&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 11:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749623#M14409</guid>
      <dc:creator>josevg1981</dc:creator>
      <dc:date>2025-07-11T11:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with checkpoint logs</title>
      <link>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749631#M14410</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311348"&gt;@josevg1981&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like this is an rsyslog configuration issue, rather than a Splunk problem however I'll do my best to help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check your rsyslog configuration and verify message size limits&amp;nbsp;in&amp;nbsp;/etc/rsyslog.conf&amp;nbsp;- what is your $MaxMessageSize? Try increasing:&lt;/P&gt;&lt;PRE&gt;$MaxMessageSize 64k&lt;/PRE&gt;&lt;P&gt;Check for any template formatting&amp;nbsp;that might be stripping content, does the template output the %msg% content?&lt;/P&gt;&lt;PRE&gt;# Look for custom templates that only capture certain fields
$template CheckPointFormat,"%timestamp% %hostname% %programname%: %msg%\n"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 14:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749631#M14410</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-11T14:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: trouble with checkpoint logs</title>
      <link>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749699#M14411</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;livehybrid :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ty , i try to change the default template for this&amp;nbsp;&amp;nbsp;Template="RSYSLOG_SyslogProtocol23Format" and now it works !!!! Ty for thew help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 07:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/trouble-with-checkpoint-logs/m-p/749699#M14411</guid>
      <dc:creator>josevg1981</dc:creator>
      <dc:date>2025-07-14T07:59:35Z</dc:date>
    </item>
  </channel>
</rss>

