cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Employee+
Employee+

*New* Splunk App for Check Point Logs

Hello all,

I’m happy to announce about a new Splunk app for Check Point logs.

Check Point brings you an advanced and real-time threat analysis and reporting tool for Splunk. The Check Point App for Splunk allows you to respond to security risks immediately and gain network true insights.

You can collect and analyze millions of logs from all Check Point technologies and platforms across networks, Cloud, Endpoints and Mobile.

(view in My Videos)

Key features are:

  • Infinity Dashboards
    • General overview
    • Top attacks
    • Detected and prevented events
    • Events timeline
    • Blades statistics
  • Cyber Attack View – a unique ability to aggregate Check Point events per attack vector (cross all blades)
    • Reconnaissance actions against the network
    • Delivery methods
    • Malicious emails
    • Malicious file download
    • Server Exploit
    • Infected hosts
  • SandBlast Events – predefined aggregation for mail and web attack vectors
  • CIM Support – Check Point logs are mapped into CIM (Common Information Model) and can be analyzed using standard dashboards (such as Splunk Enterprise Security)
    More information on CIM can be found here: https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview
  • Fast Deploy – an easy and fast deployment using the new Log Exporter

 

 

The app can be downloaded from Splunk base: Check Point App for Splunk | Splunkbase 

 

 

For any question, comment or suggestion, please contact cp_splunk_app_support@checkpoint.com.

 

Thank you!

Dan Zada, Group Manager.

Labels (1)
Tags (2)
15 Replies

Re: *New* Splunk App for Check Point Logs

Do we have to use the new Log Exporter to take full advantage of the new Splunk App?

Employee+
Employee+

Re: *New* Splunk App for Check Point Logs

Yes, you have to use the new log exporter.

0 Kudos

Re: *New* Splunk App for Check Point Logs

and a Log Exporter version that supports the new "splunk" format and sending logs in semi-unified mode. 

  • R80.20 Jumbo Take 5 or higher, (sk137592)
  • R80.10 Jumbo Take 56 or higher, (sk116380)
  • R77.30 Jumbo Take 292 or higher, (sk106162)
D_W
Nickel

Re: *New* Splunk App for Check Point Logs

Can I not use SmartReport to generate such kind of Views/Reports? I do not get the point why to use splunk? Maybe you can explain more specific Smiley Happy

Employee+
Employee+

Re: *New* Splunk App for Check Point Logs

SmartEvent has most of those views out of the box.

Many customers are using Splunk as another place to keep logs related to ALL security and IT vendors. This is why we created this integration and allowed our customers to export the logs using the log exporter to any SIEM vendor.

0 Kudos

Re: *New* Splunk App for Check Point Logs

I have a few questions:

1. Is Splunk multivendor compatible

2. Do it require additional license to run Splunk App?

3. Can it also be used to pull out health check reports on physical & virtual firewalls/VPNs? (CPU, Memory Utilization, disk space, traffic volume and availability etc)

Employee+
Employee+

Re: *New* Splunk App for Check Point Logs

1. Our Splunk app is working on top of Check Point logs.

2. Not that I know of.

3. No, you can only pull logs

Re: *New* Splunk App for Check Point Logs

Question on #3 -  I am trying to pull health status related logs to Splunk. How do I do that?

 

0 Kudos
Nüüül
Silver

Re: *New* Splunk App for Check Point Logs

Awesome! Thanks for sharing!

0 Kudos

Re: *New* Splunk App for Check Point Logs

We've been using the Log Exporter for a few months now. The Checkpoint logs are getting forwarded to a central syslog sever (rsyslog) and then forwarded to splunk (also via syslog). We've written a custom Splunk checkpoint app to split the fields and using the QOS Dashboards for some nice graphs.

When reading the instructions for the Checkpoint App for Splunk, it mentions using a "splunk" format (which I don't think got mentioned in the original Log Exporter article):

cp_log_export add name my_exporter target-server 192.168.1.1 target-port 12001 protocol tcp format splunk read-mode semi-unified

My questions are:

  1. Can we still use the central syslog server as an intermediate step before shipping the logs to Splunk using the "splunk" format?
  2. Does the Check Point 'cache' the logs if there is a network or splunk server issue?
  3. Is there any loss in functionality if we can use the syslog as an intermediate step?
  4. How does the 'splunk' format differ from the 'syslog' format?

 

Employee
Employee

Re: *New* Splunk App for Check Point Logs

Hi,

Regarding your questions:

  1. Yes, you can still use your central syslog server before shipping these logs to your Splunk server.
    Make sure to choose format 'splunk' when exporting the logs out from your MGMT / Log Server.
  2. In case of network issue, Log Exporter knows to deal with caching the logs. When the connection is available again, the logs will be sent.
  3. No.
  4. When choosing splunk as format in Log Exporter configuration, the logs will be sent in the format that our new application knows how to parse the data correctly. the format contains dedicated header, delimiters and etc.
    Therefore, when working with our new app, the format must be splunk in order to get the data correctly into Splunk server.

Re: *New* Splunk App for Check Point Logs

Hi,

Has there been an RFE raised to export pcap files (packet capture) via Log Exporter to SIEMs - in my case Splunk?

I am referring to Packet Capture for Certain Protections in the IPS has been enabled.

0 Kudos
Employee+
Employee+

Re: *New* Splunk App for Check Point Logs

Hi,

Yes, we have RFE for that and it will be released later this year.

We are going to implement that using management APIs, meaning the exporter will add additional field representing the blob ID, to every log. Using the management API you will be able to get the blob.

Stay tuned for more updates in SK122323.

0 Kudos

Re: *New* Splunk App for Check Point Logs

Will this also capture and report on Audit events like who created/deleted/modified what and who logged in etc?

0 Kudos

Re: *New* Splunk App for Check Point Logs

yes, answered earlier on CheckMates... in the targetconfiguration.xml file, there is a parameter called log_types like this:

<log_types></log_types><!--all[default]|log|audit/-->

The default is for both security logs and audit logs to be sent, but you can change this to only send one or the other.