- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Log Exporter - Splunk Integration Update
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log Exporter - Splunk Integration Update
Hello Everyone,
We are currently in advanced stages of developing a Log Exporter update that will add CIM support.
This will give us better Splunk integration for CIM oriented apps and dashboards (e.g. Splunk Enterprise Security).
We are currently looking for customers who wish to test this new feature (in either their lab or production) and share their feedback with us.
I would also really appreciate if in your email you could also add the following details:
- what version of Check Point do you use? And what version of Splunk server?
- Is your Splunk environment installed as a single-instance or is it a distributed environment?
- Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on?
The new update will also enable the Log Exporter to work in a semi-unified mode.
For those who are unfamiliar with this setting, it means that updates are unified with their original log before they are exported. This makes the information in the update log complete and makes the update log itself more readable (in raw mode you had to manually search for the original log to make sense of the update).
Best Regards,
Yonatan
- Labels:
-
Integrations
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Yonatan,
I am deploying R80.10 Checkpoint FW(3 Tie architecture) in AWS. I am using Terraform for resource provisioning and Ansible for config automation. I am looking for the solution to add Ansible config to send log from Checkpoint FW to Splunk server, details are below,
- what version of Check Point do you use? R80.10
- And what version of Splunk server? Splunk Version7.0.1
- Is your Splunk environment installed as a single-instance or is it a distributed environment? : Distributed.
- Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on? No.
Please suggest on this, if possible please share the example of script should look like.
Thank you,
Amit Chaubey
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Yonatan,
I am deploying R80.10 Checkpoint FW(3 Tie architecture) in AWS. I am using Terraform for resource provisioning and Ansible for config automation. I am looking for the solution to add Ansible config to send log from Checkpoint FW to Splunk server, details are below,
- what version of Check Point do you use? R80.10
- And what version of Splunk server? Splunk Version7.0.1
- Is your Splunk environment installed as a single-instance or is it a distributed environment? : Distributed.
- Have you already tested out previous releases of the Log Exporter or is this your first use of the add-on? No.
Please suggest on this, if possible please share the example of script should look like.
Thank you,
Amit Chaubey
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Amit,
Sorry for the late response.
We've basically closed off the EA at this point, but after some internal debate and since we haven't tested this new feature on AWS we decided that this is an interesting use case and will gladly add you to the EA cycle as well.
Just a small clarification based on your post - the logs will be sent from the gateway to the management/log server and will be forwarded from there to the Splunk server. They are not sent directly from the gateway to Splunk.
If you still wish to participate please contact me offline at (edited as the feature is already GA)
Regards,
Yonatan

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In case anyone has missed it, this is GA now. For more information see this discussion: *New* Splunk App for Check Point Logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, Mr. Yonatan.
Are you still interested in working with customers trying to implement the Check Point App for Splunk in a distributed Splunk Enterprise deployment?
Gaia R80.20
Distributed Splunk 7.2.4
First use of Log Exporter, somewhat new to Checkpoint, Splunk noob. The only available Checkpoint documentation that I've been able to find for integrating Log Exporter with Splunk appears to be for a standalone Splunk environment.
Thanks---David
