Hello All,
I have a question about Splunk's App for Checkpoint OPSEC LEA from our firewall administrator. We currently ingest about 60GB/day of CP logs, but the admin only sees about 15GB/day of logs on his CP device. Why is there such a high discrepancy? As far as I can tell, the Splunk app is working as it should and we are not getting any errors.
Any thoughts?
thanks
ed
Check Splunk's license_usage log to find out distribution of the 60GB license usage by index/host/source/sourcetype and validate that with your Firewall admin that he's including all those index/host/source/sourcetype into his calculation.
index=_internal sourcetype=splunkd source=*license_usage.log type=usage
fields - idx (index) h (host) s (source) and st (sourcetype)
Check Splunk's license_usage log to find out distribution of the 60GB license usage by index/host/source/sourcetype and validate that with your Firewall admin that he's including all those index/host/source/sourcetype into his calculation.
index=_internal sourcetype=splunkd source=*license_usage.log type=usage
fields - idx (index) h (host) s (source) and st (sourcetype)
I think I figured it out. Check Point logs are in binary format and the add-on converts the data from binary to ascii format which would account for the 4x difference in log sizes.