Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 841 Bytes

bc80861f-64f6-4eaa-87c5-f51540ccac27.md

File metadata and controls

35 lines (28 loc) · 841 Bytes

Mappings: Check Point Drop

Input Requirements

Input Value
Vendor Check Point
Product Firewall
Log Format JSON
Event ID Regex Pattern Drop|drop

Record Output

Output Value
Vendor CheckPoint
Product Firewall and VPN
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
device_ip origin
dstDevice_ip dst
dstPort service
ipProtocol proto
severity severity This is a lookup field. More info to come in the catalog later...
srcDevice_ip src
srcDevice_natIp xlatesrc
srcPort s_port
success None The static text false is populated in this schema field.
timestamp time We expect the orginal record value of time is in the format epoch