Source types for the Splunk Add-on for Check Point Log Exporter
The Splunk Add-on for Check Point Log Exporter provides the following source types and CIM compatibility.
Sourcetype | Event type | CIM compliance |
---|---|---|
cp_log
|
cp_tcp_attack | Intrusion Detection |
cp_network_communicate | Network Traffic | |
cp_change | Change | |
cp_change_audit | Change | |
cp_logout_logs | Change | |
cp_change_network | Change | |
cp_alert | Alerts | |
cp_malware_attack | Malware Attacks | |
cp_ids_attack | Intrusion Detection | |
cp_auth_logs | Authentication | |
cp_endpoint_activity | Inventory | |
cp_email_logs | ||
cp_web | Web | |
cp_log:syslog
|
cp_tcp_attack | Intrusion Detection |
cp_network_communicate | Network Traffic | |
cp_change | Change | |
cp_change_audit | Change | |
cp_logout_logs | Change | |
cp_change_network | Change | |
cp_alert | Alerts | |
cp_malware_attack | Malware Attacks | |
cp_ids_attack | Intrusion Detection | |
cp_auth_logs | Authentication | |
cp_endpoint_activity | Inventory | |
cp_email_logs | ||
cp_web | Web |
Lookups for the Splunk Add-on for Check Point Log Exporter | Release notes for the Splunk Add-on for Check Point Log Exporter |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!