Getting Data In

Checkpoint with Splunk on Windows

Splunk Employee
Splunk Employee

Does the Checkpoint LEA app work on windows? or has anyone tweaked it to work?

Tags (1)
1 Solution

Splunk Employee
Splunk Employee

just tested the Windows FW1-loggrabber executable (1.11.1) and it works well with R75.

http://sourceforge.net/projects/fw1-loggrabber/

I'm sure the splunk APP can be tweaked to accommodate the event data:

C:\set4bits\FW1-Loggrabber>fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) R75 - Build 254
C:\set4bits\FW1-Loggrabber>fw1-loggrabber.exe |more
loc=0|time=2011-06-17 17:51:38|action=ctl|orig=172.16.12.200|i/f_dir=inbound|i/f
_name=daemon|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|log_sys
_message=Log file has been switched to: 2011-06-17_152203_1.log
loc=1|time=2011-06-17 17:51:43|action=accept|orig=172.16.12.200|i/f_dir=inbound|
i/f_name=E1G606|has_accounting=0|uuid=<4dfbf69f,00000000,c80c10ac,0000ffff>|prod
uct=VPN-1 & FireWall-1|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={9D0262
9E-B095-40D3-AE39-FA4DA8BB5F01};mgmt=WIN-BVJQ2GHXBVN;date=1308353659;policy_name
=Standard]|src=172.16.12.138|s_port=60819|dst=172.16.12.200|service=18184|proto=
tcp|rule=4

View solution in original post

New Member

Hi all,
loggrabber works fine, but I can't make it work correctly with splunk.

Did anyone already manage to fetch logs vialea on windows splunk ?

thanks.

0 Karma

Splunk Employee
Splunk Employee

just tested the Windows FW1-loggrabber executable (1.11.1) and it works well with R75.

http://sourceforge.net/projects/fw1-loggrabber/

I'm sure the splunk APP can be tweaked to accommodate the event data:

C:\set4bits\FW1-Loggrabber>fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) R75 - Build 254
C:\set4bits\FW1-Loggrabber>fw1-loggrabber.exe |more
loc=0|time=2011-06-17 17:51:38|action=ctl|orig=172.16.12.200|i/f_dir=inbound|i/f
_name=daemon|has_accounting=0|uuid=<00000000,00000000,00000000,00000000>|log_sys
_message=Log file has been switched to: 2011-06-17_152203_1.log
loc=1|time=2011-06-17 17:51:43|action=accept|orig=172.16.12.200|i/f_dir=inbound|
i/f_name=E1G606|has_accounting=0|uuid=<4dfbf69f,00000000,c80c10ac,0000ffff>|prod
uct=VPN-1 & FireWall-1|__policy_id_tag=product=VPN-1 & FireWall-1[db_tag={9D0262
9E-B095-40D3-AE39-FA4DA8BB5F01};mgmt=WIN-BVJQ2GHXBVN;date=1308353659;policy_name
=Standard]|src=172.16.12.138|s_port=60819|dst=172.16.12.200|service=18184|proto=
tcp|rule=4

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!