<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Active-Response Add-on for Splunk in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/95534#M92877</link>
    <description>&lt;P&gt;Hi, any updates on the documentation and configuration steps?&lt;/P&gt;
&lt;P&gt;What feedback from users/customers?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 17:06:15 GMT</pubDate>
    <dc:creator>ToRo</dc:creator>
    <dc:date>2020-08-28T17:06:15Z</dc:date>
    <item>
      <title>Check Point Active-Response Add-on for Splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/22253#M92875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are happy to announce the Check Point Active Response Add-on is now available on Splunkbase:&amp;nbsp;&lt;A class="link-titled" href="https://splunkbase.splunk.com/app/4115/" title="https://splunkbase.splunk.com/app/4115/"&gt;Check Point Adaptive Response Add-on | Splunkbase&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This initiative was created to help SOCs (Security Operations Centers) create and deliver a consolidated threat response across all products. This new AR Add-on will allow our joint customers to extract malicious IOCs from the Splunk environment and push them to Check Point gateways for enforcement:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Fetch IOC values =&amp;gt; user can write search queries to automatically fetch IOCs or manually input IOCs from Splunk ES Incident Review Dashboard&lt;/LI&gt;&lt;LI&gt;Create a csv file with IOC values/types/metadata&lt;/LI&gt;&lt;LI&gt;Push csv file to Check Point gateway for policy enforcement&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Check Point Gateway side of this is based on the Custom Intelligence Feeds" feature, currently in Early Availability for R80.10 Gateways.&lt;/P&gt;&lt;P&gt;For more information and to join the EA, refer to:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193"&gt;What is "Custom Intelligence Feeds" feature?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 17:13:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/22253#M92875</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-27T17:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Active-Response Add-on for Splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/22254#M92876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ICYMI, we have documented this in&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/AdaptiveResponsive_Splunk/html_frameset.htm" title="https://sc1.checkpoint.com/documents/AdaptiveResponsive_Splunk/html_frameset.htm"&gt;Check Point Adaptive Response Add-on for Splunk v1.0 User Guide&lt;/A&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/22254#M92876</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-11-20T19:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Active-Response Add-on for Splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/95534#M92877</link>
      <description>&lt;P&gt;Hi, any updates on the documentation and configuration steps?&lt;/P&gt;
&lt;P&gt;What feedback from users/customers?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 17:06:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Active-Response-Add-on-for-Splunk/m-p/95534#M92877</guid>
      <dc:creator>ToRo</dc:creator>
      <dc:date>2020-08-28T17:06:15Z</dc:date>
    </item>
  </channel>
</rss>

