Hello,
We are ingesting Checkpoint logs through an Edge Processor to our SCP. We have deployed Splunk Add-on for Check Point Log Exporter in SCP but events are not parsing properly. I show you in a screenshot:
We only can use these fields, related to the EP
Could someone help us?
Thank's in advance
Hello adrifesa95. Are you using the Splunk Add-on for Check Point Log Exporter, or the older Splunk Add-on for Check Point OPSEC LEA? If the newer one, there is a section on the docs referring to troubleshooting when its not parsing due to depth limit and how to increase it...
https://docs.splunk.com/Documentation/AddOns/released/CheckPointLogExporter/Troubleshoot
any help?