Getting Data In

Checkpoint events are not being parsed properly

adrifesa95
Engager

Hello,

 

We are ingesting Checkpoint logs through an Edge Processor to our SCP. We have deployed Splunk Add-on for Check Point Log Exporter in SCP but events are not parsing properly. I show you in a screenshot:

adrifesa95_0-1717668699295.pngadrifesa95_0-1717668699295.png

We only can use these fields, related to the EP

Could someone help us?

Thank's in advance

Labels (1)
0 Karma

nyc_jason
Splunk Employee
Splunk Employee

Hello adrifesa95. Are you using the Splunk Add-on for Check Point Log Exporter, or the older Splunk Add-on for Check Point OPSEC LEA? If the newer one, there is a section on the docs referring to troubleshooting when its not parsing due to depth limit and how to increase it...

https://docs.splunk.com/Documentation/AddOns/released/CheckPointLogExporter/Troubleshoot

0 Karma

adrifesa95
Engager

any help?Captura.PNGCaptura.PNG

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...