We got the below alert on our Qrdar SIEM server. I have removed IPs from the log and used X,Y,Z instead. The source is standby firewall but the origin and originsicname are showing as active firewall details.
Alert - Checkpoint AntiVirus or AntiMalware Alert Detected
LEEF:2.0|Check Point|Anti Malware|1.0|Detect|devTime=1690067244 srcPort=33516 url=yearinesents.xyz signature=Maze.TC.ov malware=Maze policyName=DCFirewallPolicy cat=Anti Malware sev=8 action=Detect ifdir=outbound ifname=Sync loguid={0xa79f6f9e,0xcdebc05b,0x4a8f2902,0x14c2509a} origin=X.X.X.X originsicname=CN\=PHY-NWK-DC-FRW-02,O\=CLUSTER..zzn8zj sequencenum=880 version=5 confidence_level=1 dst=Y.Y.Y.Y log_id=2 malware_action=DNS query for a C&C site malware_rule_id={CE6C83BD-AB76-4B53-819F-98CEC479FD68} policy_time=1689944558 protection_id=00340173A protection_type=DNS reputation proto=17 rule_name=Internet access to Manager and Gateway rule_uid=3947ba36-03d7-4ada-b748-90ee083d1200 scope=Z.Z.Z.Z service=53 session_id={0x64bc544c,0xc,0xa2a3aaca,0xc69bb62e} smartdefense_profile=Optimized Threat Prevention src=Z.Z.Z.Z layer_uuid={269BAA7D-91DD-4356-A634-594DD105B2FE} malware_rule_id={CE6C83BD-AB76-4B53-819F-98CEC479FD68} smartdefense_profile=Optimized Threat Prevention vendor_list=Check Point ThreatCloud