Hi at all,
I installed the Check Point App for Splunk and I found a strange behaviour:
at first the name is "Check Point App for Splunk" but the folder name is "TA-check-point-app-for-splunk" ,th...
See more...
Hi at all,
I installed the Check Point App for Splunk and I found a strange behaviour:
at first the name is "Check Point App for Splunk" but the folder name is "TA-check-point-app-for-splunk" ,that's strange: it's an App or a TA?
But this isn't my problem:
installing this app I found that, for each event, there are some fields (date, time and rule_action) that are duplicated with the same value, in other words, for each event there is two times the same field and the same value (e.g. rule_action="allowed").
Has anyone encountered this problem?
Ciao and thanks,
Giuseppe