Thanks for the answer, let me understand... i need to install a Universal Forwarder in the checkpoint and the add-on in my Splunk?.
The add-on was installed an configured in the splunk.
1) You need install HW
2) then install CheckPoint add-on to HW
3) then configure you CheckPoint to send logs to HW
4) then configure HW to send logs to Splunk Light (you need add-on for extract fields in Splunk Light too)