We got the below alert on our Qrdar SIEM server. I have removed IPs from the log and used X,Y,Z instead. The source is standby firewall but the origin and originsicname are showing as active firewall details.
Alert - Checkpoint AntiVirus or AntiMalware Alert Detected
LEEF:2.0|Check Point|Anti Malware|1.0|Detect|devTime=1690067244   srcPort=33516     url=yearinesents.xyz    signature=Maze.TC.ov    malware=Maze      policyName=DCFirewallPolicy  cat=Anti Malware  sev=8 action=Detect     ifdir=outbound    ifname=Sync loguid={0xa79f6f9e,0xcdebc05b,0x4a8f2902,0x14c2509a}  origin=X.X.X.X      originsicname=CN\=PHY-NWK-DC-FRW-02,O\=CLUSTER..zzn8zj      sequencenum=880   version=5   confidence_level=1      dst=Y.Y.Y.Y log_id=2    malware_action=DNS query for a C&C site   malware_rule_id={CE6C83BD-AB76-4B53-819F-98CEC479FD68}      policy_time=1689944558  protection_id=00340173A protection_type=DNS reputation      proto=17    rule_name=Internet access to Manager and Gateway      rule_uid=3947ba36-03d7-4ada-b748-90ee083d1200   scope=Z.Z.Z.Z    service=53  session_id={0x64bc544c,0xc,0xa2a3aaca,0xc69bb62e}     smartdefense_profile=Optimized Threat Prevention      src=Z.Z.Z.Z      layer_uuid={269BAA7D-91DD-4356-A634-594DD105B2FE}     malware_rule_id={CE6C83BD-AB76-4B53-819F-98CEC479FD68}      smartdefense_profile=Optimized Threat Prevention      vendor_list=Check Point ThreatCloud