Getting Data In

Splunk App for Check Point

gstefancyk
Path Finder

I am currently pulling logs from my Check Point Management station successfully and can search on them with no issues. I am trying to get the Splunk app for Check Point to display data and am looking for some clarification on what indexes need to be created?

Currently I have all Check Point non-audit logs going into the default index. Can anyone clarify for me what index the Splunk App for Check Point looks at and what index or indexes I need to create?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

The Splunk app for Checkpoint seems to use checkpoint_indexas a macro behind most of the searches. That macro is simple and says index=checkpoint, so your data needs to be indexed in the index "checkpoint". (You could - though I don't recommend it - change that macro to point to main. More explanation can be given, but mostly it's just you shouldn't use main.)

Speaking of which, did you set up the Splunk add-on for Check Point OPSEC LEA as the docs mention?

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

The Splunk app for Checkpoint seems to use checkpoint_indexas a macro behind most of the searches. That macro is simple and says index=checkpoint, so your data needs to be indexed in the index "checkpoint". (You could - though I don't recommend it - change that macro to point to main. More explanation can be given, but mostly it's just you shouldn't use main.)

Speaking of which, did you set up the Splunk add-on for Check Point OPSEC LEA as the docs mention?

0 Karma

gstefancyk
Path Finder

Thanks rich7177.

I must have missed that little section at the bottom of the App details page that says log everything to "checkpoint". I have configured the opsec lea add on to log to index checkpoint and data is now populating the Splunk App for Check Point.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...