Check Point Multi-Domain Management (Provider-1) 샘플 이벤트 메시지
이 샘플 이벤트 메시지를 사용하여 IBM QRadar와의 성공적인 통합을 확인하십시오.
중요: 형식화 문제로 인해 메시지 형식을 텍스트 편집기에 붙여넣은 후 캐리지 리턴 또는 줄 바꾸기 문자를 제거하십시오.
LEEF 프로토콜 사용 시 Check Point Multi-Domain Management (Provider-1) 샘플 메시지
샘플 1: 다음 샘플 이벤트 메시지는 클럭 디먼이 생성한 정보용 이벤트를 표시합니다.
LEEF:2.0|Check Point|Syslog|1.0|Check Point Log|cat=Syslog devTime=1537528801 ifdir=inbound loguid={0x0,0x0,0x0,0x0} origin=172.16.150.106 sequencenum=1 version=5 default_device_message=<78>crond[30156]: (root) CMD (/usr/lib/sa/sa1 1 1) facility=clock daemon syslog_severity=Informational
샘플 2: 다음 샘플 이벤트 메시지는 애플리케이션에 대한 특정 세부사항 (예: 애플리케이션의 카테고리, 이름, 설명, ID및 특성) 을 포함하는 애플리케이션 제어 이벤트를 표시합니다. 이 샘플에는 애플리케이션에 액세스할 수 있는 사용자 및 규칙 기반과 일치하는 일치 카테고리를 판별하는 규칙도 포함되어 있습니다.
LEEF:2.0|Check Point|Application Control|1.0|Allow|cat=Application Control devTime=1393855342 srcPort=35275 sev=8 ifdir=outbound ifname=eth1-05 loguid={0x54f411c8,0x9,0xbd0317ac,0x187a} origin=10.1.76.67 version=1 app_category=Network Protocols app_desc=Telnet is a network protocol used on the Internet or local area networks to provide a bidirectional interactive text-oriented communications facility using a virtual terminal connection. User data is interspersed in-band with Telnet control information in an 8-bit byte oriented data connection over the Transmission Control Protocol (TCP). Supported from: R75. app_id=60095597 app_properties=Allows remote connect, High Risk, Network Protocols app_rule_id={C54A11A6-BDE9-11DF-9B35-C21D241F6A6A} app_rule_name=Any Allow Log app_sig_id=60095597:1 appi_name=Telnet Protocol dst=10.9.240.147 matched_category=Network Protocols origin_sic_name=CN\\=ny1,O\\=ny..8ye75g product=Application Control proto=6 proxy_src_ip=10.0.36.27 service=50008 src=10.0.36.27