Security

Checkpoint Logs - and no OPSEC

BunnyHop
Contributor

Is there a way to grab logs from Checkpoint FW-1 without using OPSEC? Any suggestions will be appreciated ;).

0 Karma

mpf
Explorer

Hi, I'm using 'fw log -l -n -p' to export the logs to a file. You'll need to setup a sourcetype as per http://answers.splunk.com/questions/11592/parsing-checkpoint-firewall-log-dates to splunk understands the timestamp.

Take a look at 'fw log -h' for other options such as tailing the log which might be usable in a scripted input.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...