Hi
We have installed Splunk 6.6.1 on Windows.
And we have checkpoint 1430 appliance managed localy.
I have installed "Splunk Add-on for Check Point Tracker and Syslog by QOS" and "Check Point Analytics App by QOS", configured checkpoint to send logs to syslog - splunk server.
I can find log by filter "sourcetype="qos_syslog""
But i could not see data in Check Point Analytics App by QOS via syslog: No results found.
Hi Kovalkovds,
Please check your "sourcetype" filter in Check Point analytics app by QOS.
It should by qos_syslog not opsec. By default sourcetype filter will be selected to "opsec" type.