In our company, we monitor CheckPoint. To determine the source of the event, it is important for us to know the value of the "ProductName" field, that is, to know the name of the blade. At the end of some logs we see characters like " id=...] " . How can we fix this problem? An example of the full log is below.
Log [Fields@X.X.X.X.X.X.X duration="*** Confidential ***" last_hit_time="*** Confidential ***" update_count="*** Confidential ***" creation_time="*** Confidential ***" connection_count="*** Confidential ***" aggregated_log_count="*** Confidential ***" url_count="*** Confidential ***" src="*** Confidential ***" dst="*** Confidential ***" proto="*** Confidential ***" client_type_os="*** Confidential ***" web_client_type="*** Confidential ***" web_server_type="*** Confidential ***" user="*** Confidential ***" src_user_name="*** Confidential ***" src_machine_name="*** Confidential ***" src_user_dn="*** Confidential ***" snid="*** Confidential ***" dst_user_name="*** Confidential ***" dst_machine_name="*** Confidential ***" dst_user_dn="*** Confidential ***" UserCheck_incident_uid="*** Confidential ***" UserCheck="*** Confidential ***" log_id="*** Confidential ***" user_status="*** Confidential ***" portal_message="*** Confidential ***" UserCheck_Confirmation_Level="*** Confidential ***" frequency="*** Confidential ***" UserCheck_Interaction_name="*** Confidential ***" service_id="*** Confidential ***" https_inspection_action="Inspect" inzone="*** Confidential ***" outzone="*** Confidential ***" UP_match_table="*** Confidential ***" ROW_START="*** Confidential ***" match_id="*** Confidential ***" layer_uuid="*** Confidential ***" layer_name="*** Confidential ***" rule_uid="*** Confidential ***" rule_name="Internet for PC" ROW_END="*** Confidential ***" ROW_START="*** Confidential ***" match_id="*** Confidential ***" layer_uuid="*** Confidential ***" layer_name="*** Confidential ***" rule_uid="*** Confidential ***" rule_name="White List for ALL" ROW_END="*** Confidential ***" UP_match_table="*** Confidential ***" UP_action_table="*** Confidential ***" ROW_START="*** Confidential ***" action="*** Confidential ***" ROW_END="*** Confidential ***" ROW_START="*** Confidential ***" action="*** Confidential ***" ROW_END="*** Confidential ***" UP_action_table="*** Confidential ***" UP_par...]
Thanks in advance for your reply!