Security

How can I use Splunk to retrieve my CheckPoint Firewall Rules?

JeanC
Engager

How can I use Splunk to retrieve my CheckPoint Firewall Rules

Tags (2)
0 Karma

mgonter_splunk
Splunk Employee
Splunk Employee

You will need a Heavy Forwarder with the Splunk Add-on For OPSEC LEA: http://docs.splunk.com/Documentation/OPSEC-LEA. It really all depends on how your CheckPoint Environment is setup. The Add-On use LEA-Logger to pull the logs via a rest call in to a Heavy Forwarder were they are unpackaged, transformed and sent to an indexer.

You have to use a Heavy Forwarder so you can configure it over the GUI. Once it's configured you're good to go.

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...