Security

How can I use Splunk to retrieve my CheckPoint Firewall Rules?

JeanC
Engager

How can I use Splunk to retrieve my CheckPoint Firewall Rules

Tags (2)
0 Karma

mgonter_splunk
Splunk Employee
Splunk Employee

You will need a Heavy Forwarder with the Splunk Add-on For OPSEC LEA: http://docs.splunk.com/Documentation/OPSEC-LEA. It really all depends on how your CheckPoint Environment is setup. The Add-On use LEA-Logger to pull the logs via a rest call in to a Heavy Forwarder were they are unpackaged, transformed and sent to an indexer.

You have to use a Heavy Forwarder so you can configure it over the GUI. Once it's configured you're good to go.

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...