Getting Data In

Logging Aggregation for Checkpoint Firewalls Logs

daniel_augustyn
Contributor

I am going slightly over my license limit from time to time because of the Checkpoint firewall logs. Is there a way to aggregate some of the firewalls logs before start indexing them into the Splunk indexers? Or the only option would be to add another 20GB of license to Splunk.

Tags (1)
0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

I'm not aware of any option to do this. You could potentially try to hack your own via transforms or unarchive_cmd (search on answers for examples of either), but the Check point stuff can't really be aggregated easily.

View solution in original post

0 Karma

David
Splunk Employee
Splunk Employee

I'm not aware of any option to do this. You could potentially try to hack your own via transforms or unarchive_cmd (search on answers for examples of either), but the Check point stuff can't really be aggregated easily.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...