All Apps and Add-ons

Splunk Add-on for Check Point POSEC LEA: How can I tell Splunk to not index all ICMP logs and DNS logs coming from Splunk LEA Add-on (Checkpoint)?

ektasiwani
Communicator

Hi,

I am using Checkpoint opsec lea to fetch checkpoint logs and the number of logs which I will get is very high.
How can I tell Splunk to not index all ICMP logs and DNS logs coming from Splunk LEA Add-on (Checkpoint)

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...