The Snare Server is capable of receiving logs from Checkpoint Firewall 1 Firewalls via the syslog protocol.
The Snare Server can filter on a wide variety of fields within the CheckPoint source data, including:
- Date/Time
- Source Address
- Destination Address
- Destination Port
- Packet ReturnCode (success/failure/information)
- Source Firewall
- Action (accept / drop)
- Source Interface
- Source Port
- Protocol
Snare can provide drill-down access to the raw log data, via overview components such as a '15 minute pattern map', and horizontal bar graphs by source/destination/destination port.
Firewall1Log 0 2004-07-11 12:00:04 10.0.1.22 drop qfe1 10.0.1.31 47997 10.0.1.136 161 24 service: snmp num: 1 type: log i/f_dir: inbound len: 117 product: firewall