Hi, I have problem with parsing log in Splunk Add-on for Check Point Log Exporter. I have install it in both SH and HF, but log from checkpoint not parsing properly. I have try change REGEX to ([a-zA-Z0-9_-]+)[:=]+([^|]+) and try to change DEPTH_LIMIT to 200000 like in troubleshooting said but it still not working.
Can you give me some advice?
Thank you so much !
Your problem description is a bit vague.
What do you mean by "not working"?
What does your ingestion process look like?
Have you set proper source types?
Does your linebreaking work properly? Timestamp recognition?
Do your events get any fields extracted or none at all?
Did you configure event export on the Checkpoint's side properly?