<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log Exporter - Splunk Integration Update in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12794#M93788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently in advanced stages of developing a Log Exporter update that will add CIM support.&lt;/P&gt;&lt;P&gt;This will give us better Splunk integration for CIM oriented apps and dashboards (e.g. Splunk Enterprise Security).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently looking for customers who wish to test this new feature (in either their lab or production) and share their feedback with us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also really appreciate if in your email you could also add the following details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what version of Check Point do you use? And what version of Splunk server?&lt;/LI&gt;&lt;LI&gt;Is your Splunk environment installed as a single-instance or is it a distributed environment?&lt;/LI&gt;&lt;LI&gt;Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The new update will also enable the Log Exporter to work in a semi-unified mode.&lt;/P&gt;&lt;P&gt;For those who are unfamiliar with this setting, it means that updates are unified with their original log before they are exported. This makes the information in the update log complete and makes the update log itself more readable (in raw mode you had to manually search for the original log to make sense of the update).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jul 2018 16:01:25 GMT</pubDate>
    <dc:creator>Yonatan_Philip</dc:creator>
    <dc:date>2018-07-25T16:01:25Z</dc:date>
    <item>
      <title>Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12794#M93788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently in advanced stages of developing a Log Exporter update that will add CIM support.&lt;/P&gt;&lt;P&gt;This will give us better Splunk integration for CIM oriented apps and dashboards (e.g. Splunk Enterprise Security).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently looking for customers who wish to test this new feature (in either their lab or production) and share their feedback with us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also really appreciate if in your email you could also add the following details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what version of Check Point do you use? And what version of Splunk server?&lt;/LI&gt;&lt;LI&gt;Is your Splunk environment installed as a single-instance or is it a distributed environment?&lt;/LI&gt;&lt;LI&gt;Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The new update will also enable the Log Exporter to work in a semi-unified mode.&lt;/P&gt;&lt;P&gt;For those who are unfamiliar with this setting, it means that updates are unified with their original log before they are exported. This makes the information in the update log complete and makes the update log itself more readable (in raw mode you had to manually search for the original log to make sense of the update).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2018 16:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12794#M93788</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-07-25T16:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12795#M93789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yonatan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am deploying&amp;nbsp;R80.10 Checkpoint&amp;nbsp;FW(3 Tie architecture) in AWS. I am using Terraform for resource provisioning and Ansible for config automation. I am looking for the solution to add Ansible config to send log from Checkpoint FW to Splunk server, details are below,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="color: #333333; background-color: #ffffff; border: 0px; padding: 0px 0px 0px 30px;"&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;what version of Check Point do you use? R80.10&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;And what version of Splunk server?&amp;nbsp; &amp;nbsp;Splunk Version7.0.1&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;Is your Splunk environment installed as a single-instance or is it a distributed environment?&amp;nbsp; &amp;nbsp;: Distributed.&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on? No.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest on this, if possible please&amp;nbsp;share the example of script should look like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amit Chaubey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2018 19:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12795#M93789</guid>
      <dc:creator>Amit_Chaubey</dc:creator>
      <dc:date>2018-09-15T19:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12796#M93790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Hi Yonatan,&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;I am deploying&amp;nbsp;R80.10 Checkpoint&amp;nbsp;FW(3 Tie architecture) in AWS. I am using Terraform for resource provisioning and Ansible for config automation. I am looking for the solution to add Ansible config to send log from Checkpoint FW to Splunk server, details are below,&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;UL style="color: #333333; background-color: #ffffff; border: 0px; padding: 0px 0px 0px 30px;"&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;what version of Check Point do you use? R80.10&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;And what version of Splunk server?&amp;nbsp; &amp;nbsp;Splunk Version7.0.1&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;Is your Splunk environment installed as a single-instance or is it a distributed environment?&amp;nbsp; &amp;nbsp;: Distributed.&lt;/LI&gt;&lt;LI style="border: 0px; font-weight: inherit; margin: 0.5ex 0px;"&gt;Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on? No.&lt;/LI&gt;&lt;/UL&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Please suggest on this, if possible please&amp;nbsp;share the example of script should look like.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Amit Chaubey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 10:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12796#M93790</guid>
      <dc:creator>Amit_Chaubey</dc:creator>
      <dc:date>2018-09-25T10:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12797#M93791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the late response.&lt;/P&gt;&lt;P&gt;We've basically closed off the EA at this point, but after some internal debate and since we haven't tested this new feature on AWS we decided that this is an interesting use case and will gladly add you to the EA cycle as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a small clarification based on your post - the logs will be sent from the gateway to the management/log server and will be forwarded from there to the Splunk server. They are not sent directly from the gateway to Splunk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still wish to participate please contact me offline at (edited as the feature is already GA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2018 08:29:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12797#M93791</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-09-27T08:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12798#M93792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In case anyone has missed it, this is GA now. For more information see this discussion:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/10286"&gt;*New* Splunk App for Check Point Logs&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 18:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/12798#M93792</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-11-23T18:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Log Exporter - Splunk Integration Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/63057#M93793</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; Mr.&amp;nbsp;&lt;SPAN&gt;Yonatan.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you still interested in working with customers trying to implement the Check Point App for Splunk in a distributed Splunk Enterprise deployment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Gaia R80.20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Distributed Splunk 7.2.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;First use of Log Exporter, somewhat new to Checkpoint, Splunk noob.&amp;nbsp; The only available Checkpoint documentation that I've been able to find for integrating Log Exporter with Splunk appears to be for a standalone Splunk environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks---David&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 13:54:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Exporter-Splunk-Integration-Update/m-p/63057#M93793</guid>
      <dc:creator>David_James1</dc:creator>
      <dc:date>2019-09-18T13:54:42Z</dc:date>
    </item>
  </channel>
</rss>

