Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Add-on for Check Point OPSEC LEA: How to configure props and transforms to filter out action=drop events from Checkpoint data?

$
0
0
Hi guys, I'm trying to delete the events *action=drop* of Checkpoint firewalls. I've already set my stanzas (opt/splunk/etc/system/ local) props.conf and transform.conf as follows, but it did not work. **props.conf** ########## FILTER OUT FIREWALL ########## [source::(/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity XXXXX)] TRANSFORMS-null = setnull **transforms.conf** ########## FILTER OUT FIREWALL ########## [setnull] REGEX=(.*)drop DEST_KEY = queue FORMAT = nullQueue I tried several REGEX, but did not work. Can someone help me? Thanks in advance!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>