Perfection is attained, not when no more can be added, but when no more can be removed. (Il semble que la perfection soit atteinte non quand il n'y a plus rien à ajouter, mais quand il n'y a plus rien à retrancher.) Antoine de Saint Exupéry
Thursday, September 28, 2006
Checkpoint FW-1 log exporting
The thing I didn't mention that you quickly find out when importing Checkpoint logs into a database is that Checkpoint have a non-fixed format for exporting logs - only those fields that have values appear in the export, and as for the order of those fields - I'm pretty certain it depends on the phase of the moon ;-) I'll post the little script that gets around that with some Perl later - it's quite simple, but not everyone who might need to load FW-1 logs into a database wants to learn Perl (or any scripting/text-processing language) in order to do so.
Subscribe to:
Post Comments (Atom)
2 comments:
I never actually published this comment and forgot all about it...the script is actually available in my GSEC Gold paper in the SANS reading room at http://www.sans.org/reading_room/whitepapers/firewalls/check_point_firewalls_rulebase_cleanup_and_performance_tuning_32884
New path:
http://www.sans.org/reading-room/whitepapers/firewalls/check-point-firewalls-rulebase-cleanup-performance-tuning-32884
Post a Comment