Getting Data In

Checkpoint events are not being parsed properly

adrifesa95
Engager

Hello,

 

We are ingesting Checkpoint logs through an Edge Processor to our SCP. We have deployed Splunk Add-on for Check Point Log Exporter in SCP but events are not parsing properly. I show you in a screenshot:

adrifesa95_0-1717668699295.png

We only can use these fields, related to the EP

Could someone help us?

Thank's in advance

Labels (1)
0 Karma

nyc_jason
Splunk Employee
Splunk Employee

Hello adrifesa95. Are you using the Splunk Add-on for Check Point Log Exporter, or the older Splunk Add-on for Check Point OPSEC LEA? If the newer one, there is a section on the docs referring to troubleshooting when its not parsing due to depth limit and how to increase it...

https://docs.splunk.com/Documentation/AddOns/released/CheckPointLogExporter/Troubleshoot

0 Karma

adrifesa95
Engager

any help?Captura.PNG

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...