Getting Data In

Firewall checkpoint for windows 8

christinmb
Path Finder

Is it possible to index Check Point firewall logs in Splunk for windows?

0 Karma
1 Solution

pajohnston
Explorer

I don't think you can using the Splunk-supplied OPSEC LEA for CheckPoint app as it only works under Linux or Solaris. You'd need a separate Linux or Solaris Splunk instance running the Checkpoint app and forward the logs to your Windows Splunk instance. I use this setup and it works ok.

If you can't run an instance on anything but Windows for some reason, then the solution outlined in this post might help. I've not tried this method, though, so I can't comment on how well it works.

View solution in original post

ashokqos
Path Finder

If you are looking for a simplified solution I suggest you try the follow Add-ON.

https://splunkbase.splunk.com/app/2996/

This add-on collect firewall logs in syslog format and extracts all the necessary fields. You can use any other Check Point App on top of this Add-on.

0 Karma

pajohnston
Explorer

I don't think you can using the Splunk-supplied OPSEC LEA for CheckPoint app as it only works under Linux or Solaris. You'd need a separate Linux or Solaris Splunk instance running the Checkpoint app and forward the logs to your Windows Splunk instance. I use this setup and it works ok.

If you can't run an instance on anything but Windows for some reason, then the solution outlined in this post might help. I've not tried this method, though, so I can't comment on how well it works.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...