Getting Data In

Checkpoint with Splunk on Windows

Michael_Wilde
Splunk Employee
Splunk Employee

Does the Checkpoint LEA app work on windows? or has anyone tweaked it to work?

Tags (1)
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

just tested the Windows FW1-loggrabber executable (1.11.1) and it works well with R75.

http://sourceforge.net/projects/fw1-loggrabber/

I'm sure the splunk APP can be tweaked to accommodate the event data:

C:\set4bits\FW1-Loggrabber>fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) R75 - Build 254
C:\set4bits\FW1-Loggrabber>fw1-loggrabber.exe |more
loc=0|time=2011-06-17 17:51:38|action=ctl|orig=172.16.12.200|i/f_dir=inbound|i/f
_name=daemon|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|log_sys
_message=Log file has been switched to: 2011-06-17_152203_1.log
loc=1|time=2011-06-17 17:51:43|action=accept|orig=172.16.12.200|i/f_dir=inbound|
i/f_name=E1G606|has_accounting=0|uuid=<4dfbf69f,00000000,c80c10ac,0000ffff>|prod
uct=VPN-1 & FireWall-1|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={9D0262
9E-B095-40D3-AE39-FA4DA8BB5F01};mgmt=WIN-BVJQ2GHXBVN;date=1308353659;policy_name
=Standard]|src=172.16.12.138|s_port=60819|dst=172.16.12.200|service=18184|proto=
tcp|rule=4

View solution in original post

nicolasfigaro
New Member

Hi all,
loggrabber works fine, but I can't make it work correctly with splunk.

Did anyone already manage to fetch logs vialea on windows splunk ?

thanks.

0 Karma

Chubbybunny
Splunk Employee
Splunk Employee

just tested the Windows FW1-loggrabber executable (1.11.1) and it works well with R75.

http://sourceforge.net/projects/fw1-loggrabber/

I'm sure the splunk APP can be tweaked to accommodate the event data:

C:\set4bits\FW1-Loggrabber>fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) R75 - Build 254
C:\set4bits\FW1-Loggrabber>fw1-loggrabber.exe |more
loc=0|time=2011-06-17 17:51:38|action=ctl|orig=172.16.12.200|i/f_dir=inbound|i/f
_name=daemon|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|log_sys
_message=Log file has been switched to: 2011-06-17_152203_1.log
loc=1|time=2011-06-17 17:51:43|action=accept|orig=172.16.12.200|i/f_dir=inbound|
i/f_name=E1G606|has_accounting=0|uuid=<4dfbf69f,00000000,c80c10ac,0000ffff>|prod
uct=VPN-1 & FireWall-1|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={9D0262
9E-B095-40D3-AE39-FA4DA8BB5F01};mgmt=WIN-BVJQ2GHXBVN;date=1308353659;policy_name
=Standard]|src=172.16.12.138|s_port=60819|dst=172.16.12.200|service=18184|proto=
tcp|rule=4
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...