Splunk Enterprise

Checkpoint Firewall Log Timestamps

cfairbairn
New Member

I'm running Splunk Light 7.1.3 on a Windows 2012 R2 server. I have some text logs from Checkpoint firewalls - unfortunately I don't have direct access to the firewall appliances themselves.

An example of line data that I'm working with is:

"" "5Sep2018" "23:58:59" "" "" "Log" "Drop" "<#>" "" "" "" "" "" "" "" "" "" "t" "" ""

I'm using the WebGUI data import tool to import the text files. I can't seem to get Splunk to recognise the timestamps.

I've used the following timestamp format:

%e%b%Y %k:%M:%S

And a couple of different variations (%d, %H) etc. No luck.

I get the error "Could not use strptime to parse timestamp..."

Any idea on what I'm doing wrong?

0 Karma

HiroshiSatoh
Champion

I got it in this format.

%d%b%Y %H:%M:%S
0 Karma

cfairbairn
New Member

Thanks. I have tried that time format also without luck.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...