**Splunk Add-on for Check Point OPSEC LEA is no longer supported. The 'Splunk Add-on for Check Point Log Exporter' has replaced the Splunk Add-on for OPSEC LEA for data collection. All customers should utilize it going forward.**
The Splunk Add-on for Check Point OPSEC LEA allows a Splunk software administrator to collect and analyze firewall, VPN, Anti-Virus, Anti-Bot, SmartDefense (IPS), Threat Emulation, and audit logs from Check Point standalone FW-1 firewalls, standard Multi-Domain Security Management (Provider-1) environments, and Provider-1 environments using the Multi-Domain Log Module (MLM). After the Splunk platform indexes the events, you can analyze the data using the prebuilt panels included with the add-on.
This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.
Resources
Log in to report this app listing