Hey Folks,
I am working on building a parser for one of the SIEM, and we are going to support CheckPoint Harmony Mobile.
I have few queries regarding this:
1. I could not find ArcSight format on the community or in the docs. Can someone provide the exact CEF log reference guide or fields explanation. I could find a post about syslog format, but I'm looking for CEF format.
2. Can I get sample CEF logs somewhere in the docs or community for network protection feature like phishing, URL filtering, file protection, anti bot etc?
3. I am getting little bit confused in Harmony Mobile and Sandblast Cloud for office 365. Is it the same product or feature which you can integrate with Harmony Mobile or a separate product?
Thank you in advance!