<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic *New* Splunk App for Check Point Logs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15873#M91023</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I’m happy to announce about a new Splunk app for Check Point logs.&lt;/P&gt;
&lt;P&gt;Check Point brings you an advanced and real-time threat analysis and reporting tool for Splunk. The Check Point App for Splunk allows you to respond to security risks immediately and gain network true insights.&lt;/P&gt;
&lt;P&gt;You can collect and analyze millions of logs from all Check Point technologies and platforms across networks, Cloud, Endpoints and Mobile.&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhyw1428h720r891" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6065297965001" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhyw1428h720r891');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhy"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;Key features are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Infinity Dashboards
&lt;UL&gt;
&lt;LI&gt;General overview&lt;/LI&gt;
&lt;LI&gt;Top attacks&lt;/LI&gt;
&lt;LI&gt;Detected and prevented events&lt;/LI&gt;
&lt;LI&gt;Events timeline&lt;/LI&gt;
&lt;LI&gt;Blades statistics&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Cyber Attack View – a unique ability to aggregate Check Point events per attack vector (cross all blades)
&lt;UL&gt;
&lt;LI&gt;Reconnaissance actions against the network&lt;/LI&gt;
&lt;LI&gt;Delivery methods&lt;/LI&gt;
&lt;LI&gt;Malicious emails&lt;/LI&gt;
&lt;LI&gt;Malicious file download&lt;/LI&gt;
&lt;LI&gt;Server Exploit&lt;/LI&gt;
&lt;LI&gt;Infected hosts&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;SandBlast Events – predefined aggregation for mail and web attack vectors&lt;/LI&gt;
&lt;LI&gt;CIM Support – Check Point logs are mapped into CIM (Common Information Model) and can be analyzed using standard dashboards (such as Splunk Enterprise Security)&lt;BR /&gt;More information on CIM can be found here: &lt;A href="https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Fast Deploy – an easy and fast deployment using the new Log Exporter&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The app can be downloaded from Splunk base: &lt;A class="link-titled" title="https://splunkbase.splunk.com/app/4293/#/overview" href="https://splunkbase.splunk.com/app/4293/#/overview" target="_blank" rel="noopener"&gt;Check Point App for Splunk | Splunkbase&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;User Guide –&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;SK about the Log Exporter – &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk122323" target="_blank" rel="noopener"&gt;http://supportcontent.checkpoint.com/solutions?id=sk122323&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For any question, comment or suggestion, please contact &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:cp_splunk_app_support@checkpoint.com" target="_blank" rel="noopener"&gt;cp_splunk_app_support@checkpoint.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Dan Zada, Group Manager.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 21:02:56 GMT</pubDate>
    <dc:creator>Dan_Zada</dc:creator>
    <dc:date>2021-06-22T21:02:56Z</dc:date>
    <item>
      <title>*New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15873#M91023</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I’m happy to announce about a new Splunk app for Check Point logs.&lt;/P&gt;
&lt;P&gt;Check Point brings you an advanced and real-time threat analysis and reporting tool for Splunk. The Check Point App for Splunk allows you to respond to security risks immediately and gain network true insights.&lt;/P&gt;
&lt;P&gt;You can collect and analyze millions of logs from all Check Point technologies and platforms across networks, Cloud, Endpoints and Mobile.&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhyw1428h720r236" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6065297965001" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhyw1428h720r236');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/VtNmpnaDE6r8qAO0DVTGg_gN5xzjLNhy"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;Key features are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Infinity Dashboards
&lt;UL&gt;
&lt;LI&gt;General overview&lt;/LI&gt;
&lt;LI&gt;Top attacks&lt;/LI&gt;
&lt;LI&gt;Detected and prevented events&lt;/LI&gt;
&lt;LI&gt;Events timeline&lt;/LI&gt;
&lt;LI&gt;Blades statistics&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Cyber Attack View – a unique ability to aggregate Check Point events per attack vector (cross all blades)
&lt;UL&gt;
&lt;LI&gt;Reconnaissance actions against the network&lt;/LI&gt;
&lt;LI&gt;Delivery methods&lt;/LI&gt;
&lt;LI&gt;Malicious emails&lt;/LI&gt;
&lt;LI&gt;Malicious file download&lt;/LI&gt;
&lt;LI&gt;Server Exploit&lt;/LI&gt;
&lt;LI&gt;Infected hosts&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;SandBlast Events – predefined aggregation for mail and web attack vectors&lt;/LI&gt;
&lt;LI&gt;CIM Support – Check Point logs are mapped into CIM (Common Information Model) and can be analyzed using standard dashboards (such as Splunk Enterprise Security)&lt;BR /&gt;More information on CIM can be found here: &lt;A href="https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Fast Deploy – an easy and fast deployment using the new Log Exporter&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The app can be downloaded from Splunk base: &lt;A class="link-titled" title="https://splunkbase.splunk.com/app/4293/#/overview" href="https://splunkbase.splunk.com/app/4293/#/overview" target="_blank" rel="noopener"&gt;Check Point App for Splunk | Splunkbase&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;User Guide –&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/App_for_Splunk/html_frameset.htm&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;SK about the Log Exporter – &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk122323" target="_blank" rel="noopener"&gt;http://supportcontent.checkpoint.com/solutions?id=sk122323&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For any question, comment or suggestion, please contact &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:cp_splunk_app_support@checkpoint.com" target="_blank" rel="noopener"&gt;cp_splunk_app_support@checkpoint.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Dan Zada, Group Manager.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 21:02:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15873#M91023</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2021-06-22T21:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15874#M91024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;Do we have to use the new Log Exporter to take full advantage of the new Splunk App? &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15874#M91024</guid>
      <dc:creator>Jack_Shultz</dc:creator>
      <dc:date>2018-11-13T19:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15875#M91025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you have to use the new log exporter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2018 07:19:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15875#M91025</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2018-11-14T07:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15876#M91026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I not use SmartReport to generate such kind of Views/Reports? I do not get the point why to use splunk? Maybe you can explain more specific &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2018 19:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15876#M91026</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2018-11-14T19:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15877#M91027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SmartEvent has most of those views out of the box.&lt;/P&gt;&lt;P&gt;Many customers are using Splunk as another place to keep logs related to ALL security and IT vendors. This is why we created this integration and allowed our customers to export the logs using the log exporter to any SIEM vendor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 06:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15877#M91027</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2018-11-15T06:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15878#M91028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a few questions:&lt;/P&gt;&lt;P&gt;1. Is Splunk multivendor compatible&lt;/P&gt;&lt;P&gt;2. &lt;SPAN style="color: #1f497d; font-size: 11pt;"&gt;Do&amp;nbsp;it require additional license to run Splunk App?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt;"&gt;3. &lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;Can it also be used to pull out health check reports on physical &amp;amp; virtual firewalls/VPNs? (CPU, Memory Utilization, disk space, traffic volume and availability etc)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: medium; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 14:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15878#M91028</guid>
      <dc:creator>Yemi_Awojide</dc:creator>
      <dc:date>2018-11-15T14:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15879#M91029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome! Thanks for sharing!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2018 17:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15879#M91029</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2018-11-15T17:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15880#M91030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and a Log Exporter version that supports the new "splunk" format and sending logs in semi-unified mode.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;R80.20 Jumbo Take 5 or higher,&amp;nbsp;(&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk137592" style="color: #ff9933;" target="_blank"&gt;sk137592&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;R80.10 Jumbo Take 56 or higher, (&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk116380" style="color: #ff9933;" target="_blank" title=""&gt;sk116380&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;R77.30 Jumbo Take 292 or higher, (&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk106162" style="color: #ff9933;" target="_blank" title=""&gt;sk106162&lt;/A&gt;)&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 18:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15880#M91030</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-11-16T18:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15881#M91031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Our Splunk app is working on top of Check Point logs.&lt;/P&gt;&lt;P&gt;2. Not that I know of.&lt;/P&gt;&lt;P&gt;3. No, you can only pull logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 07:47:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15881#M91031</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2018-11-18T07:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15882#M91032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've been using the Log Exporter for a few months now. The Checkpoint logs are getting forwarded to a central syslog sever (rsyslog) and then forwarded to splunk (also via syslog). We've written a custom Splunk checkpoint app to split the fields and using the QOS Dashboards for some nice graphs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When reading the instructions for the Checkpoint App for Splunk, it mentions using a "splunk" format (which I don't think got mentioned in the original Log Exporter article):&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;cp_log_export add name my_exporter target-server 192.168.1.1 target-port 12001 protocol tcp &lt;STRONG&gt;format splunk&lt;/STRONG&gt; read-mode semi-unified&lt;/CODE&gt;&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;My questions are:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Can we still use the central syslog server as an intermediate step before shipping the logs to Splunk using the "splunk" format?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Does&amp;nbsp;the Check Point 'cache' the logs if there is a network or splunk server issue?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Is there any loss in functionality if we can use the syslog as an intermediate step?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;How does the 'splunk' format differ from the 'syslog' format?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2018 05:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15882#M91032</guid>
      <dc:creator>c9a127e7-d053-3</dc:creator>
      <dc:date>2018-12-05T05:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15883#M91033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Regarding your questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Yes, you can still use your central syslog server before shipping these logs to your Splunk server.&lt;BR /&gt;Make sure to choose format 'splunk' when exporting the logs out from your MGMT / Log Server.&lt;/LI&gt;&lt;LI&gt;In case of network issue, Log Exporter knows to deal with caching the logs. When the connection is available again, the logs will be sent.&lt;/LI&gt;&lt;LI&gt;No.&lt;/LI&gt;&lt;LI&gt;When choosing splunk as format in Log Exporter configuration, the logs will be sent in the format that our new application knows how to parse the data correctly. the format contains dedicated header, delimiters and etc.&lt;BR /&gt;Therefore, when working with our new app, the format must be splunk in order to get the data correctly into Splunk server.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 15:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15883#M91033</guid>
      <dc:creator>Shay_Hibah</dc:creator>
      <dc:date>2018-12-19T15:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15884#M91034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has there been an RFE raised to export pcap files (packet capture) via Log Exporter to SIEMs - in my case Splunk?&lt;/P&gt;&lt;P&gt;I am referring to Packet Capture for Certain Protections in the IPS has been enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 03:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15884#M91034</guid>
      <dc:creator>Rudy_Hodges</dc:creator>
      <dc:date>2019-03-04T03:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15885#M91035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, we have RFE for that and it will be released later this year.&lt;/P&gt;&lt;P&gt;We are going to implement that using management APIs, meaning the exporter will add additional field representing the blob ID, to every log. Using the management API you will be able to get the blob.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stay tuned for more updates in SK122323.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 07:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/15885#M91035</guid>
      <dc:creator>Dan_Zada</dc:creator>
      <dc:date>2019-03-04T07:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/48086#M91036</link>
      <description>&lt;P&gt;Will this also capture and report on Audit events like who created/deleted/modified what and who logged in etc?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 10:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/48086#M91036</guid>
      <dc:creator>Chris_Phillips</dc:creator>
      <dc:date>2019-03-21T10:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/48349#M91037</link>
      <description>yes, answered earlier on CheckMates... in the targetconfiguration.xml file, there is a parameter called log_types like this:&lt;BR /&gt;&lt;BR /&gt;    &amp;lt;log_types&amp;gt;&amp;lt;/log_types&amp;gt;&amp;lt;!--all[default]|log|audit/--&amp;gt;&lt;BR /&gt;&lt;BR /&gt;The default is for both security logs and audit logs to be sent, but you can change this to only send one or the other.</description>
      <pubDate>Fri, 22 Mar 2019 22:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/48349#M91037</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-03-22T22:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/57368#M91038</link>
      <description>&lt;P&gt;Question on #3 -&amp;nbsp; I am trying to pull health status related logs to Splunk. How do I do that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 15:33:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/57368#M91038</guid>
      <dc:creator>et_splunker</dc:creator>
      <dc:date>2019-07-03T15:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70413#M91039</link>
      <description>&lt;P&gt;Are there plans to release a Splunk dashboard that would allow us to mimic SmartConsole's Log section? The Dashboard announced here is a good overview from Threat, but its not a good replacement for SmartConsole. We'd like something that we can search by IP and have them displayed in a useful manner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also in our environment we have found that sending the logs via method TCP creates problems (even after changing the thread count from the default of 12 to just 1) and have resorted to UDP only.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 14:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70413#M91039</guid>
      <dc:creator>Josh_Dillig</dc:creator>
      <dc:date>2019-12-13T14:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70507#M91040</link>
      <description>&lt;P&gt;I'm curious on the TCP problems:&lt;/P&gt;
&lt;P&gt;Do you mean performance issues? Please elaborate on any log-exporter TCP related issues you had.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2019 09:27:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70507#M91040</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2019-12-15T09:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70603#M91041</link>
      <description>&lt;P&gt;We would see only 1 or 2 of the 12 threads establishing TCP sockets. We did have some CLMs that would complete all 12 sockets, but in general it was unstable. We never was able to determine conclusively that it was on the MLM side instead of the Splunk side. There is a TAC case opened (&lt;SPAN&gt;6-0001798729)&lt;/SPAN&gt; on it along with a CFG task. There is a tcpdump in the SR, we saw SYN-ACKs coming back but never being ACK'd.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 18:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/70603#M91041</guid>
      <dc:creator>Josh_Dillig</dc:creator>
      <dc:date>2019-12-16T18:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: *New* Splunk App for Check Point Logs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/72042#M91042</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;according to Splunkbase the app only supports Splunk 7.2.&lt;/P&gt;&lt;P&gt;Has anyone tried it out on 7.3+? Are there any known issues? Is an update planned to support the most current Splunk versions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 12:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-Splunk-App-for-Check-Point-Logs/m-p/72042#M91042</guid>
      <dc:creator>Datarockz</dc:creator>
      <dc:date>2020-01-10T12:16:38Z</dc:date>
    </item>
  </channel>
</rss>

