Splunk Enterprise

Check Point App for Splunk

theboss
Engager

Hi,

I am using the free app "Check Point App for Splunk" on Splunk Enterprise 9.4. Splunk Enterprise will be upgraded to version 10. The URL Check Point App for Splunk | Splunkbase says it is supported on Splunk Enterprise version 9.4, but not on v10. I presume it may or may not work on Splunk Enterprise v10. Can someone using Splunk Enterprise v10 confirm whether the free app "Check Point App for Splunk" works as expected?

 

Thanks!

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Adding to the already provided answers - this app was released by Checkpoint two years ago before certain business events happened. Therefore it is highly probable that due to political reasons the app will not be updated anymore by the vendor.

There is an alternative app - https://splunkbase.splunk.com/app/5478

Its status is "archived" (which could warrant pinging the support) but it should work OK and it's Splunk supported.

0 Karma

kknairr
Contributor

@theboss This app was built by Checkpoint itself, and the latest app version released almost two years ago where Splunk version 10 was not released at that time, hence not showing in compatibility section. I don't have a use case for Checkpoint specific, but general approach which I follow is to test it in our Dev splunk setup running with v10 and run the app inputs there to test for any errors related to Splunk version. You may also follow similar approach. Thanks.

>>

If this post addressed your question, you can:

  • Give it karma to show appreciation 👍
  • Mark it as the solution if it solved your issue ✔️
  • Add a comment if you’d like more details ✏️

Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.

>>

livehybrid
SplunkTrust
SplunkTrust

Hi @theboss 

I dont use the app myself but Ive had a look through the code for it and theres nothing that jumps out at that would cause too much concern ie deprecated python version dependency. However there is some Javascript in some of the dashboards although I personally havent experienced issues with this from 9->10.

If possible it would be worth installing a dev version of 10.x and installing the app to check you still have the same functionality without errors that you currently have. Things like the props/transforms etc shouldnt be an issue from 9->10.

In the meantime you could also raise an issue on their GitHub repo (https://github.com/CheckPointSW/Check_Point_App_for_Splunk) asking if they can confirm and/or update for v10.x

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...