Security

Logs are encrypted

changhieuzi
New Member

Hi,
I collect logs from Checkpoint firewall and these logs are encrypted. How do Splunk read and analyze this log ?

Tags (1)
0 Karma

sowings
Splunk Employee
Splunk Employee
0 Karma

changhieuzi
New Member

Hi !
I will explain in detail my network diagram and my problem below
Network diagram
Checkpoint FW >> Syslog server >> Splunk
(mean: The first Checkpoint FW generates logs >> These logs are forwarded to syslog server which is Windows server 2k8(then user copies these logs to storage device) >> upload offline to Splunk server to index).
My problem is the logs data which is encrypted when they came out from FW
How do I do to read the logs?
Thank you !!

There are 2 pics which are logs in display. I uploaded they to my dropbox
https://www.dropbox.com/s/iyoht5ttyz02w9k/logviewer1.png
https://www.dropbox.com/s/qftwn15y12bguws/logviewer2.png

0 Karma

changhieuzi
New Member

There are 2 pics which are logs in display. I uploaded they to my dropbox
https://www.dropbox.com/s/iyoht5ttyz02w9k/logviewer1.png

https://www.dropbox.com/s/qftwn15y12bguws/logviewer2.png

0 Karma

changhieuzi
New Member

Hi !
I will explain in detail my network diagram and my problem below

Network diagram
Checkpoint FW >> Syslog server >> Splunk
(mean: The first Checkpoint FW generates logs >> These logs are forwarded to syslog server which is Windows server 2k8(then user copies these logs to storage device) >> upload offline to Splunk server to index).

My problem is the logs data which is encrypted when they came out from FW

How do I do to read the logs?

Thank you !!

0 Karma

Ayn
Legend

Really encrypted or just in Checkpoint's binary format?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can write a decrypting script and run it as a scripted input.

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...