I think that Check Point should designate some internal resources to creation of parsers for dominant SIEM systems.
Same situation is encountered with Alert Logic. They are parsing Windows and Cisco logs using pre-built parsers but CPlog to Syslog output is, for the moment, a raw text.
Since there was a mention of native Syslog support coming back in later releases, (it was only briefly supported in R77.30), that pretty much means that the format will change again.
This situation is causing some frustration with clients that are increasingly required to utilize SIEM services.