Splunk Enterprise

How to integrate Checkpoint and TrendMicro with Splunk light?

Isaor
New Member

Hello,

I am trying to integrate a checkpoint and TrendMicro tool, but when configuring this via syslog and opsec, it doesn't appear in my forward management. How is it possible to integrate this in Splunk light?

0 Karma

skulk
Explorer

Hi,

about Check Point:

You need install Splunk Add-on for Check Point OPSEC LEA but it supported only by Heavy Forwarder (HW) only, so you need install HF, which will receive Check Point logs and then send them to your Splunk Light.

0 Karma

Isaor
New Member

Hi!!!!!!

Thanks for the answer, let me understand... i need to install a Universal Forwarder in the checkpoint and the add-on in my Splunk?.

The add-on was installed an configured in the splunk.

0 Karma

skulk
Explorer

1) You need install HW
2) then install CheckPoint add-on to HW
3) then configure you CheckPoint to send logs to HW
4) then configure HW to send logs to Splunk Light (you need add-on for extract fields in Splunk Light too)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...