Getting Data In

Checkpoint events are not being parsed properly

adrifesa95
Engager

Hello,

 

We are ingesting Checkpoint logs through an Edge Processor to our SCP. We have deployed Splunk Add-on for Check Point Log Exporter in SCP but events are not parsing properly. I show you in a screenshot:

adrifesa95_0-1717668699295.png

We only can use these fields, related to the EP

Could someone help us?

Thank's in advance

Labels (1)
0 Karma

nyc_jason
Splunk Employee
Splunk Employee

Hello adrifesa95. Are you using the Splunk Add-on for Check Point Log Exporter, or the older Splunk Add-on for Check Point OPSEC LEA? If the newer one, there is a section on the docs referring to troubleshooting when its not parsing due to depth limit and how to increase it...

https://docs.splunk.com/Documentation/AddOns/released/CheckPointLogExporter/Troubleshoot

0 Karma

adrifesa95
Engager

any help?Captura.PNG

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...