Check Point Multi-Domain Management (Provider-1) 샘플 이벤트 메시지

이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.

중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.

LEEF 프로토콜 사용 시 Check Point Multi-Domain Management (Provider-1) 샘플 메시지

샘플 1: 다음 샘플 이벤트 메시지는 클럭 디먼이 생성한 정보용 이벤트를 표시합니다.

LEEF:2.0|Check Point|Syslog|1.0|Check Point Log|cat=Syslog	devTime=1537528801	ifdir=inbound	loguid={0x0,0x0,0x0,0x0}	origin=172.16.150.106	sequencenum=1	version=5	default_device_message=<78>crond[30156]: (root) CMD (/usr/lib/sa/sa1 1 1) 	facility=clock daemon	syslog_severity=Informational

샘플 2: 다음 샘플 이벤트 메시지는 애플리케이션에 대한 특정 세부사항 (예: 애플리케이션의 카테고리, 이름, 설명, ID및 특성) 을 포함하는 애플리케이션 제어 이벤트를 표시합니다. 이 샘플에는 애플리케이션에 액세스할 수 있는 사용자 및 규칙 기반과 일치하는 일치 카테고리를 판별하는 규칙도 포함되어 있습니다.

LEEF:2.0|Check Point|Application Control|1.0|Allow|cat=Application Control	devTime=1393855342	srcPort=35275	sev=8	ifdir=outbound	ifname=eth1-05	loguid={0x54f411c8,0x9,0xbd0317ac,0x187a}	origin=10.1.76.67	version=1	app_category=Network Protocols	app_desc=Telnet is a network protocol used on the Internet or local area networks to provide a bidirectional interactive text-oriented communications facility using a virtual terminal connection. User data is interspersed in-band with Telnet control information in an 8-bit byte oriented data connection over the Transmission Control Protocol (TCP). Supported from: R75.	app_id=60095597	app_properties=Allows remote connect, High Risk, Network Protocols	app_rule_id={C54A11A6-BDE9-11DF-9B35-C21D241F6A6A}	app_rule_name=Any Allow Log	app_sig_id=60095597:1	appi_name=Telnet Protocol	dst=10.9.240.147	matched_category=Network Protocols	origin_sic_name=CN\\=ny1,O\\=ny..8ye75g	product=Application Control	proto=6	proxy_src_ip=10.0.36.27	service=50008	src=10.0.36.27