Mappings: Check Point Drop
Input | Value |
---|---|
Vendor | Check Point |
Product | Firewall |
Log Format | JSON |
Event ID Regex Pattern | Drop|drop |
Output | Value |
---|---|
Vendor | CheckPoint |
Product | Firewall and VPN |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
device_ip | origin | |
dstDevice_ip | dst | |
dstPort | service | |
ipProtocol | proto | |
severity | severity | This is a lookup field. More info to come in the catalog later... |
srcDevice_ip | src | |
srcDevice_natIp | xlatesrc | |
srcPort | s_port | |
success | None | The static text false is populated in this schema field. |
timestamp | time | We expect the orginal record value of time is in the format epoch |