I think I might have found the root cause -- there are several fw rules that I've set to not log via SmartDashboard (due to a heavy activity), however they are still being sent to Splunk.
Perhaps my question would be -- is there any way to configure Check Point OPSEC LEA to skip logs for rules with the Track option set to None?
... View more