<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk add-on for Checkpoint not extracting fields in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/692417#M10134</link>
    <description>&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265129"&gt;@nguyens&lt;/a&gt;&amp;nbsp; Thanks it worked...&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2024 14:34:09 GMT</pubDate>
    <dc:creator>wali02</dc:creator>
    <dc:date>2024-07-04T14:34:09Z</dc:date>
    <item>
      <title>Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658130#M9692</link>
      <description>&lt;P&gt;I have Splunk SH Cluster ( 3 SH's in Cluster)&amp;nbsp; and we are collecting Checkpoint logs using Syslog and then Splunk HF read the Checkpoint logs (basically a flat file) and indexes into Splunk.&amp;nbsp; Now my issue is I see the events are extracted as it should when we use an add-on.&amp;nbsp; However I do not see any Checkpoint app/add-on this is installed on SH's / HF.&amp;nbsp; No manual field extractions either.&amp;nbsp; I would like to know if there is any away to check how the fields are extracted ?&lt;/P&gt;&lt;P&gt;Secondly, We also have a separate SH running ES.&amp;nbsp; On this, I don't see the events being extracted as I see it on our SH cluster.&amp;nbsp; I did try to install Splunk Add-on for Checkpoint to parse the fields and make it CIM compliant but the fields are not extracted.&amp;nbsp; I changed the sourcetype of the CP logs to match it with the add-on but still no luck.&amp;nbsp; I am using&amp;nbsp;Splunk Add-on for Check Point Log Exporter.&amp;nbsp; Appreciate your thoughts on this.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 13:55:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658130#M9692</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-09-20T13:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658134#M9694</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135347"&gt;@Navanitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what's the sourcetype of your checkpoint data?&lt;/P&gt;&lt;P&gt;usually it's renamed and fields extractions are related to the new sourcetypes.&lt;/P&gt;&lt;P&gt;This means that you have to install the CheckPoint Add on, both on SH and HF.&lt;/P&gt;&lt;P&gt;In addition, you have to associate to the checkpoint input the sourcetype "cp_log" so the Add-on can correctly modify the sourcetype.&lt;/P&gt;&lt;P&gt;Read the instructions on the Checkpoint Add-On, which one are you using?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 14:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658134#M9694</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-20T14:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658159#M9696</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using "Splunk Add-on for Check Point Log Exporter" from&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5478" target="_blank"&gt;https://splunkbase.splunk.com/app/5478&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I installed this on splunk SH and&amp;nbsp; did rename sourcetype on Splunk HF to "&lt;SPAN&gt;cp_log:syslog" as per the add-on.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 16:15:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658159#M9696</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-09-20T16:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658221#M9699</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135347"&gt;@Navanitha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;try to install it also on HF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 06:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/658221#M9699</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-21T06:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/659050#M9708</link>
      <description>&lt;P&gt;I tried installing the add-on on HF but no luck.&amp;nbsp; I am working with Splunk support on this and they figured that the KV store for Checkpoint add-on is not loading as the regex is not matching our events.&amp;nbsp; They are working on giving me a regex, will try it out once I have it.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 09:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/659050#M9708</guid>
      <dc:creator>Navanitha</dc:creator>
      <dc:date>2023-09-29T09:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/659056#M9711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135347"&gt;@Navanitha&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;publish the solution when you'll solve for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 10:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/659056#M9711</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-29T10:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/678166#M9887</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i was facing the same issue. I have changed under transforms.conf the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[kv_cp_log_format]
REGEX = ([a-zA-Z0-9_-]+)[:=]+([^|]+)

[kv_cp_syslog_log_format]
REGEX = ([a-zA-Z0-9_-]+)[:=]+"((?:[^"\\]|\\.)+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 08:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/678166#M9887</guid>
      <dc:creator>nguyens</dc:creator>
      <dc:date>2024-02-21T08:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Checkpoint not extracting fields</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/692417#M10134</link>
      <description>&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265129"&gt;@nguyens&lt;/a&gt;&amp;nbsp; Thanks it worked...&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 14:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-add-on-for-Checkpoint-not-extracting-fields/m-p/692417#M10134</guid>
      <dc:creator>wali02</dc:creator>
      <dc:date>2024-07-04T14:34:09Z</dc:date>
    </item>
  </channel>
</rss>

