Re: [logs] API for accessing Checkpoint binary log files

From: Sean Higgins (sean@private)
Date: Tue Jan 06 2004 - 14:12:58 PST

  • Next message: Rainer Gerhards: "RE: [logs] API for accessing Checkpoint binary log files"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    
    > Does anybody know of an any API that can be used to retrieve log data from
    > Checkpoints binary log files.
    > I am currently trying to develop a parser/monitoring app for the Checkpoint
    > firewall. What I am getting a set of checkpoint log files which are in
    > binary format.
    
    Check out http://www.opsec.com.  This site has programs which are compatible 
    with Check Point.  It also has the SDK for Check Point which allows you to 
    write programs to interface with Check Point directly.
    
    I have written a simple program which would talk to a Check Point NG firewall 
    directly and get the log information.  The output of this program is an XML 
    format of the logs, which I then parsed with another program, but you can use 
    this as an example of how to read the log files.  I actually created it from 
    an example in the SDK.
    
    If you have some questions, let me know.
    
                                    Sean
    
    >
    > Thanks in advance.
    >
    > Mohit Kumar
    >
    > _______________________________________________
    > LogAnalysis mailing list
    > LogAnalysis@private
    > http://lists.shmoo.com/mailman/listinfo/loganalysis
    
    - -- 
    Sean Higgins, sean@private
    http://www.systura.com - "Where information meets knowledge."
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)
    
    iD8DBQE/+zL5IiQjiOi4TA4RAg6aAKDdgYL4STiXiKF+9p9b00lxhfMAmQCgqpNQ
    yyMGez+0UBi/5t7DDfURZWM=
    =Be75
    -----END PGP SIGNATURE-----
    
    
    


    _______________________________________________ LogAnalysis mailing list LogAnalysis@private http://lists.shmoo.com/mailman/listinfo/loganalysis



    This archive was generated by hypermail 2b30 : Tue Jan 06 2004 - 20:58:36 PST