Splunk Enterprise Security

Checkpoint R80.20 integration with Checkpoint

asharma21193
New Member

I am trying to integrate Checkpoint running on Gaia OS version R80.20 to heavy forwarder. I am using checkpoint log export utility. I am using tcp port 9000 as shown below.

I have also installed Checkpoint app on heavy forwarder just to ease the integration. After installing this app, I am able to see cp_log sourctype under ADD DATA tab. But I am not able to see index where I need to forward these logs. I am just able to see only 3 indexes ( summary, main and default). But I want to forward these logs into my specific index (india_firewall) already created on splunk cloud. is there any solution of this problem or should I use syslog in order to forward message.

name: splunk
status: Running (52900)
last log read at: 25 Dec 13:14:40
debug file: /opt/CPrt-R80.20/log_exporter/targets/splunk/log/log_indexer.elg

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...