Hi all,
Currently, I using non-audit input to collect log from Checkpoint SD to Splunk but it provide object name rather ip and port. For searching easier, I would like to collect only Ip address and port number. How can I do that?
_time src src_port dest service proto action rule rule_id rule_name
2019-09-17 10:15:43 HNX-FPT-MPLS 1985 224.0.0.2 1985 udp dropped Policy_DC-HNX-Fw-CP1450 16
2019-09-17 10:15:44 10.47.1.91 54580 fo-app-stb TCP6443 tcp allowed Policy_DC-WAN-Fw-CP5200 13
2019-09-17 10:15:44 10.46.20.55 60785 S-HAN-DC01 domain-udp udp allowed Policy_DC-WAN-Fw-CP5200 13
↧