Security

Logs are encrypted

changhieuzi
New Member

Hi,
I collect logs from Checkpoint firewall and these logs are encrypted. How do Splunk read and analyze this log ?

Tags (1)
0 Karma

sowings
Splunk Employee
Splunk Employee
0 Karma

changhieuzi
New Member

Hi !
I will explain in detail my network diagram and my problem below
Network diagram
Checkpoint FW >> Syslog server >> Splunk
(mean: The first Checkpoint FW generates logs >> These logs are forwarded to syslog server which is Windows server 2k8(then user copies these logs to storage device) >> upload offline to Splunk server to index).
My problem is the logs data which is encrypted when they came out from FW
How do I do to read the logs?
Thank you !!

There are 2 pics which are logs in display. I uploaded they to my dropbox
https://www.dropbox.com/s/iyoht5ttyz02w9k/logviewer1.png
https://www.dropbox.com/s/qftwn15y12bguws/logviewer2.png

0 Karma

changhieuzi
New Member

There are 2 pics which are logs in display. I uploaded they to my dropbox
https://www.dropbox.com/s/iyoht5ttyz02w9k/logviewer1.png

https://www.dropbox.com/s/qftwn15y12bguws/logviewer2.png

0 Karma

changhieuzi
New Member

Hi !
I will explain in detail my network diagram and my problem below

Network diagram
Checkpoint FW >> Syslog server >> Splunk
(mean: The first Checkpoint FW generates logs >> These logs are forwarded to syslog server which is Windows server 2k8(then user copies these logs to storage device) >> upload offline to Splunk server to index).

My problem is the logs data which is encrypted when they came out from FW

How do I do to read the logs?

Thank you !!

0 Karma

Ayn
Legend

Really encrypted or just in Checkpoint's binary format?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can write a decrypting script and run it as a scripted input.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...