My primary goal is to index the ACL logs. No questions here.
The second goal is to also import the Checkpoint rulebase and do a bit of analysis of rule vs. the attributed log entries.
Interesting things here:
- sorting the rules by hit counts
- Finding unused rules
Can you send me in a right direction for this second goal?
- what's a good way to import and index the rulebase?
Thanks
that would be a cool feature, and is worth an enhancement request. Please file one with support?