Hi.
I need to feed SPLUNK with logs from Infinity Portal.
I read that with Infinity Portal all logs and security events are stored in the Infinity Portal’s cloud-native as datalake in cloud.
It can forwarding events, as said in the doc, as "...an easy and secure procedure to export Infinity Portal data over the Syslog protocol. You can forward logs, events, and saved application data from your Check Point Infinity Portal account to a
SIEM (Security Information and Event Management) provider, such as Splunk, QRadar, or ArcSight".
In my case I want to send these event to a Splunk ES (SaaS cloud)
Questions:
- How Can i choice the format of the log since there are different log format vendor SIEM as CEF, LEEF, maybe json for SPLUNK ?
- If there is a solution for the point 1 do i need to set up a Splunk Forwarder (Splunk syslog server) to collect these logs from Infinity Portal and then send them to a Splunk Enterprise Security SAAS ?
- Do the the Infinity Portal implement (transparently) the CheckPoint Log EXPORTER sw module on its components?
Thank you
Roby