I'm ingesting logs from the log exporter and bring them into a test environment which is a fresh install with the checkpoint app installed. The data is not CIM compatiable. For example the action values are different.
The log exporter target was set to splunk and semi_unified
check point app for splunk
Thanks for the info, but the developer is not responding to emails