OPSEC/LEA log source parameters for Nokia FireWall

If QRadar does not automatically detect the log source, add a Nokia FireWall log source on the QRadar Console by using the OPSEC/LEA protocol.

When using the OPSEC/LEA protocol, there are specific parameters that you must use.

The following table describes the parameters that require specific values to collect OPSEC/LEA events from a Nokia FireWall:
Table 1. OPSEC/LEA log source parameters for the Nokia FireWall DSM
Parameter Value
Log Source type Check Point FireWall-1
Protocol Configuration OPSEC/LEA
Log Source Identifier

Type an IP address, host name, or name to identify the event source. IP addresses or host names are better because they enable QRadar to match a log file to a unique event source.

For a complete list of OPSEC/LEA protocol parameters and their values, see OPSEC/LEA protocol configuration options.