The im_checkpoint module, provided by NXLog Enterprise Edition, can collect logs from Check Point devices over the OPSEC LEA protocol.
Example 1. Collecting Check Point Opsec LEA logs
With the following configuration, NXLog will collect logs from Check Point devices over the LEA protocol and write them to file in JSON format.
<Extension _json> Module xm_json </Extension> <Input checkpoint> Module im_checkpoint Command /opt/nxlog/bin/nx-im-checkpoint LEAConfigFile /opt/nxlog/etc/lea.conf </Input> <Output file> Module om_file File 'tmp/output' Exec $raw_event = to_json(); </Output> <Route checkpoint_to_file> Path checkpoint => file </Route>