Check Pointã»ãã¥ãªãã£ã²ãŒããŠã§ã€ã䜿çšããå Žåããã°ãåæããŠæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããæ€åºããã³åæããã¿ã¹ã¯ãéåžžã«é »ç¹ã«çºçããŸãã éåžžãçµç¹ã«ã¯ãã§ã«äœããã®ãã®ã³ã°ã·ã¹ãã ããããã¿ã¹ã¯ã¯Check Point管çãµãŒããŒãããã°ã転éãããã°ã®ãã£ã«ã¿ãŒãæ§æããããã·ã¥ããŒããã¹ã±ãžã¥ãŒã«ãªã©ãäœæããããšã§ãã ãã®ã³ãŒã¹ã§ã¯ãå éšæ©èœãšãµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠãã§ãã¯ãã€ã³ããã°ãåæããããã®ããŸããŸãªãªãã·ã§ã³ãæ€èšããæœåºã§ããæçšãªæ å ±ãšããã¡ã€ã¢ãŠã©ãŒã«ã®æ§æã«åœ¹ç«ã€æ å ±ãæ€èšããŸãã
Check Pointã®è£œåã®äžéšãšããŠãSmartEventæ©èœããããæ åœãããã³ãã¬ãŒãã«é¢ããã¬ããŒããäœæããŸãããŸããèªåã¢ã¯ã·ã§ã³ã®éå®ã»ãããæ§æããããšãã§ããŸãããããã«ã€ããŠã¯ä»ã§ã¯ãªãã®ã§ããã®åé¡ã«åŸã§æ»ããŸãã ãã®åé¡ã«ã¯ä»ã®è§£æ±ºçããããŸããããã«ã€ããŠã¯ä»ã®èšäºã§èª¬æããŸããã
- Splunk + Check Pointããã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ãåæããäŸ
- Check Point Smart Eventã ããã¬ã€ã
äžèšã®ãœãªã¥ãŒã·ã§ã³ããã¹ãŠèšå®ããã«ã¯ãç¹å®ã®è³æ Œãšå®è£ ã«å€ãã®æéãå¿ èŠã§ãã ããã§è§£æ±ºçãå¿ èŠã«ãªã£ããã©ãããŸããïŒ Check Pointã¯æè¿ããã®ã±ãŒã¹ã«æé©ãªã¢ããªã±ãŒã·ã§ã³ãSplunkçšCheck Pointã¢ããªããªãªãŒã¹ããŸãããããã¯ããã°ãšã¯ã¹ããŒã¿ãŒããŒã«ã䜿çšããŠsyslogãä»ããŠãªã¢ã«ã¿ã€ã ã§Splunkãã®ã³ã°ã·ã¹ãã ã«ããŒã¿ãéä¿¡ãããŸãã ãã®èšäºã§ã¯ããã®ãœãªã¥ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãããã³åºåã§åŸãããæ å ±ã詳现ã«æ€èšããŸãã
ã€ã³ã¹ããŒã«èŠä»¶
Check Point管çãµãŒããŒã§ã¯ãsyslogãããã³ã«ã䜿çšããŠãã°ãéä¿¡ããããã«ãã€ã³ã¹ããŒã«ãããLog ExporterããŒã«ãå¿ èŠã§ãã GAIA R80.20ã§ã¯ãLog Exporterã¯ããã©ã«ãã§ã€ã³ã¹ããŒã«ãããŸãããSplunkãã°åœ¢åŒããµããŒãããã«ã¯ãJumbo Hotfixãã€ã³ã¹ããŒã«ããå¿ èŠããããŸããLogExporterãã€ã³ã¹ããŒã«ããåã«ãJumbo HotfixããµããŒãããããã«æåã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
ä¿®æ£ããã°ã©ã ã®ããŒãžã§ã³ã®ãã¹ãŠã®èŠä»¶ã以äžã«ç€ºããŸãã
- R80.20-ãžã£ã³ãããããã£ãã¯ã¹ãã€ã¯5以äžã
- R80.10-Jumbo Hotfix Take 56以éã
- R77.30-Jumbo Hotfix Take 292以äžã
ã¢ããªã±ãŒã·ã§ã³ãæ©èœããããã«ã¯ãã·ã¹ãã ã®æå°ããŒãžã§ã³ãå°ãªããšãSplunk 6.5ã§ããã Splunk Common Information ModelïŒCIMïŒããã±ãŒãžãã€ã³ã¹ããŒã«ãããŠããå¿ èŠããããŸãã
ã€ã³ã¹ããŒã«ãšèµ·å
ã€ã³ã¹ããŒã«ããã»ã¹ã¯éåžžã«ç°¡åã§ããæåã«Log Exporterãã€ã³ã¹ããŒã«ãã次ã«Splunkã«ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãã管çãµãŒããŒã«ãã°ãéä¿¡ããããã»ã¹ãšãã°èšé²ã·ã¹ãã ã§åãå ¥ãããã»ã¹ãæ§æãããã°ã·ããã³ã°ãéå§ãããšã³ããã€ã³ããŸã§ã«ããã¹ãŠãæåŸ ã©ããã«æ©èœããããšã確èªããŸãã ãã¹ãŠã®ãã€ã³ãããã詳现ã«æ€èšããŠãã ããã
1.å¿ èŠã«å¿ããŠãžã£ã³ãããããã£ãã¯ã¹ãã€ã³ã¹ããŒã«ããŸãã
Webãã©ãŠã¶ã§GAIAããŒã¿ã«ã«ç§»åããå·ŠåŽã®ã¡ãã¥ãŒïŒã¢ããã°ã¬ãŒãïŒCPUSEïŒãã¹ããŒã¿ã¹ããã³ã¢ã¯ã·ã§ã³ïŒã§ãæšå¥šãããJumbo Hotfixããã±ãŒãžãéžæããŸããããã¯ãèŠä»¶ã®äžéãããå€ããæããã«é«ãããŒãžã§ã³ã«ãªãããã¯ã©ãŠãããã®Hotfixã®è¿œå ã§ç®çã®ããŒãžã§ã³ãæ¢ããŠã€ã³ã¹ããŒã«ããŸããããã»ã¹ã§ã¯ç®¡çãµãŒããŒã®åèµ·åãå¿ èŠã«ãªããŸãã
2. Check Pointã®ããŒãžã§ã³ãR80.20ãããäœãå ŽåãLog Exporterãã€ã³ã¹ããŒã«ããŸãã
管çã«Log Exporterãã€ã³ã¹ããŒã«ããã«ã¯ãæåã«Check PointããŒã¿ã«ããã¢ãŒã«ã€ããããŠã³ããŒãããŸã ã
次ã«ãCPUSE->ã¹ããŒã¿ã¹ããã³ã¢ã¯ã·ã§ã³ã¡ãã¥ãŒã«ç§»åããããã±ãŒãžã®ã€ã³ããŒããéžæããã¢ãŒã«ã€ããžã®ãã¹ãæå®ããŠã€ã³ããŒãããŸãã ãã®åŸãããã±ãŒãžã®è¡šç€ºããæšå¥šããã±ãŒãžã®è¡šç€ºãããããã¹ãŠã®ããã±ãŒãžã®è¡šç€ºãã«å€æŽããã€ã³ããŒãããã¢ãŒã«ã€ããéžæããŠã€ã³ã¹ããŒã«ããŸãã
3.以åã«ã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ãCIMãã€ã³ã¹ããŒã«ããŸãã
Splunk WebUIã«ç§»åãã[ã¢ããªã®ç®¡ç]-> [ä»ã®ã¢ããªã®åç §]ã§CIMããã±ãŒãžãèŠã€ããŠã€ã³ã¹ããŒã«ããŸãã
4.SplunkçšCheck Pointã¢ããªã®ã€ã³ã¹ããŒã«
ããŒã¿ã«ããã¢ãŒã«ã€ããããŠã³ããŒãããSplunk WebUIãã¢ããªã®ç®¡çããã¡ã€ã«ããã¢ããªãã€ã³ã¹ããŒã«ã«é²ã¿ãç®çã®ã¢ãŒã«ã€ããéžæããŠãã¢ããããŒããã¯ãªãã¯ããŸãã æäœãæ£åžžã«å®äºããããšãéç¥ããã®ãåŸ ã£ãŠããŸããAppsãªã¹ãã«ã¢ããªã±ãŒã·ã§ã³ã衚瀺ãããŠããããšã確èªããŠãã ããã
ãã¡ãããããã¯ã€ã³ã¹ããŒã«ãããã¢ããªã±ãŒã·ã§ã³ã®ããã«èŠããã¯ãã§ãã
syslogãä»ããŠãã°ãéä¿¡ããã«ã¯ããŸãLog Exporterããã»ã¹ãäœæãã次ã«Splunkãžã®ããŒã¿å ¥åãèšå®ããäœæããããã»ã¹ãCheck Point管çãµãŒããŒã§éå§ããå¿ èŠããããŸãã
5.ãã°ãšã¯ã¹ããŒã¿ãŒã®æ§æ
CLIã®Check Point管çãµãŒããŒã§ããšãã¹ããŒãã¢ãŒãã§æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
cp_log_export add name [domain-server <domain-server>] target-server <target-server> target-port <target-port> protocol <tcp | udp> format splunk read-mode <raw | åçµ±äž>
ããã§ãæ§æåã<target-server>ã¯ããŒã¿ãéä¿¡ããSplunkã·ã¹ãã ã®IPã¢ãã¬ã¹ã<target-port>ã¯ããŒã¿ãéä¿¡ããããŒãã§ãã
äŸïŒcp_log_export add name check_point_syslog target-server 10.10.1.159 target-port 9000 protocol tcp format splunk read-mode semi-unified
6. Splunkã§ã®ããŒã¿å ¥åã®ã»ããã¢ãã
Splunk WebUIã«ç§»åããã¡ãã¥ãŒã§[èšå®]ãéžæãã[ããŒã¿]ã»ã¯ã·ã§ã³ã§[ããŒã¿å ¥å]ãéžæããŸãã
ããŒã¿ãSplunkã«éä¿¡ãããããã³ã«ãéžæããŸãããã®äŸã§ã¯tcpã§ã[+æ°ããè¿œå ]ãéžæããŸãã
次ã«ãLog Exporterã§æå®ãããããŒã<target-port>ãå ¥åããŸãããã®å Žåã¯9000ã§ãæ¥ç¶ãåãå ¥ããIPã¢ãã¬ã¹ãããã«æå®ããŠã[Next]ãã¿ã³ãåŸ ã¡ãŸãã
ãœãŒã¹ã¿ã€ãã§ã¯ãcp_logãmethod-IPãæå®ããŸããã€ã³ããã¯ã¹ã¯ããã©ã«ãã®ãŸãŸã«ããŠããã¹ãŠã®ããŒã¿ãindex = Mainã«ãªããŸãããã®ã€ã³ããã¯ã¹ã«ä»ã®ããŒã¿ãããå Žåãæ€çŽ¢æéãå€§å¹ ã«å¢å ããå¯èœæ§ããããããå¥ã®ã€ã³ããã¯ã¹ãæå®ããããæ°ããã€ã³ããã¯ã¹ãäœæã§ããŸããã¢ããªã±ãŒã·ã§ã³èªäœã§ãæ€çŽ¢æäœãå®è¡ããã€ã³ããã¯ã¹ãçŽæ¥æå®ããå¿ èŠããããŸãã
[確èª]ãã¯ãªãã¯ãããšããã¹ãŠã®èšå®ãæ£ããããšãããããŸãã[éä¿¡]ãéžæãããšãããŒã¿å ¥åã®æ§æãå®äºããCheck Point管çãµãŒããŒãããã°ãéä¿¡ããã ãã§æžã¿ãŸãã
7.ãã°ãSplunkã«ã¢ããããŒãããããã»ã¹ãéå§ããŸã
ãšãã¹ããŒãã¢ãŒãã§ã次ã®ã³ãã³ããå ¥åããŸãã
cp_log_export restart nameãããã§æåã®ã¹ãããã§äœæãããæ§æå
äŸïŒcp_log_export restart check_point_syslog
ã»ããã¢ããã¯çµäºããŸãããã®åŸãSplunkã®æšæºã®æ€çŽ¢ã¯ãšãªã¡ã«ããºã ã䜿çšããŠããã°ãSplunkã«éä¿¡ãããããšã確èªããããã ãã«æ®ããŸãã
ããã§ãã¢ããªã±ãŒã·ã§ã³èªäœã®åäœãããã«å«ãŸããããã·ã¥ããŒããšã¬ããŒããååŸã§ããéèŠãªæ å ±ãããã³å°ãåºããçµè«ã®åæã«é²ãããšãã§ããŸãã
ãã°åæ
ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ãäžè¬æŠèŠãšè åšå¯Ÿçä¿è·ã®2ã€ã®ã»ã¯ã·ã§ã³ã«åãããŠããŸãããããã¯ããµã€ããŒæ»æã®æŠèŠããµã³ããã©ã¹ãä¿è·ãè¿œå ã®è åšå¯Ÿçã€ãã³ãã«åãããŠããŸãã åã»ã¯ã·ã§ã³ãåå¥ã«æ€èšããŸãããã
äžè¬çãªæŠèŠ
ã¢ããªã±ãŒã·ã§ã³ã®ã¡ã€ã³ããŒãžã«ã¯ãããã€ãã®ããŒãã«ãçµ±èšãã°ã©ãã衚瀺ãããŸãã ãã®å Žåã®æ å ±ã®äžéšã¯ãã²ãŒããŠã§ã€ã管çãµãŒããŒã®æ°ããã¬ãŒãäžã®ãã°ã®æ°ãªã©ãåºæ¬çãªãã®ã§ãããã»ãšãã©äœãæ°ããããšãåŠã¶ããšã¯ãªãã§ãããããã®æ å ±ã«åºã¥ããŠãè¯å®çãªå¹æãããããçµè«ãå°ãåºãããšãã§ããŸãã
ç§ã®èŠ³ç¹ãããããã§æãèå³æ·±ãèŠçŽ ã¯ãã¯ãªãã£ã«ã«æ»æã®çš®é¡ãããªã·ãŒã«ãã£ãŠèš±å¯ãããã¯ãªãã£ã«ã«æ»æãææãããã¹ããèš±å¯ãããé«ãªã¹ã¯ã¢ããªã±ãŒã·ã§ã³ã§ããçç±ã説æããŸãã
ããªã·ãŒã§èš±å¯ãããã¯ãªãã£ã«ã«æ»æã¿ã€ããã¯ãªãã£ã«ã«æ»æã«åŸã£ãŠãè åšé²æ¢ã»ãã¥ãªãã£ããªã·ãŒãæ¹åããããšãã§ããŸãïŒç¹å®ã®ã·ã°ããã£ã«ããæ€åºããé²æ¢ãžã®ã¢ã¯ã·ã§ã³ã®ç§»åããŸãã¯å¿çã¬ãã«ã®å¢å ã«ããïŒãã€ã³ãã©ã¹ãã©ã¯ãã£ã ææãã¹ããšã¯ãææããŠããå¯èœæ§ã®ãããŠãŒã¶ãŒã瀺ããŸãããããã£ãŠããŠã€ã«ã¹ãçµç¹ã®ãããã¯ãŒã¯ãééããªãããã«ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã§åå¥ã«ãã§ãã¯ãããããããã¯ãŒã¯ããéé¢ããå¿ èŠããããŸãã èš±å¯ãããé«ãªã¹ã¯ã¢ããªã±ãŒã·ã§ã³ã®å³ã«åºã¥ããŠããŠãŒã¶ãŒããããã¯ããããšãçŸåšèš±å¯ãããŠãããæã蚪åãããæœåšçã«å±éºãªã¢ããªã±ãŒã·ã§ã³ããããã¯ã§ããŸãã
ãªã¹ã¯å¥ã®ã¢ããªã±ãŒã·ã§ã³ãšURLãã£ã«ã¿ãªã³ã°ãé倧床å¥ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ããããã³ããªã·ãŒå¥ã®æ»æã¢ã¯ã·ã§ã³ã®å³ã¯ãæ¬è³ªçã«äœç³»çã§ãããçµç¹å ã®æ å ±ã»ãã¥ãªãã£ã®ç¶æ ãçµæçã«æ¹åãããã©ãããã€ãŸããã»ãã¥ãªãã£ããªã·ãŒã«å ããããå€æŽãã€ã³ãã©ã¹ãã©ã¯ãã£ãããã«ä¿è·ããã®ã«åœ¹ç«ã€ãã©ããã瀺ããŠããŸãã
ãµã€ããŒæ»æã®æŠèŠ
ãã®ããã·ã¥ããŒãã«ã¯ãææãããã¹ãããã³ãŠã€ã«ã¹ãããŠã³ããŒããããŠãŒã¶ãŒã«é¢ãã詳现æ å ±ã衚瀺ãããŸãã ããŠã³ããŒãããææãã¡ã€ã«ãšææã¡ãã»ãŒãžã§åé¢ããããšã¯éåžžã«äŸ¿å©ã§ããè åšãç¹å®ããåã ã®ãµãŒãã¹ã®è åšé²æ¢ã»ãã¥ãªãã£ããªã·ãŒãsmtpãã©ãã£ãã¯ã®ã»ãã¥ãªãã£ãããã¡ã€ã«ãhttpãšhttpsã®å¥ã®ãããã¡ã€ã«ãäœæã§ããŸãã SandBlast Protectionã¯ãææãããã¡ã€ã«ã«é¢ãããã詳现ãªæ å ±ãæäŸããŸããé倧床ã確èªããThreat Preventionã®ã»ãã¥ãªãã£ãããã¡ã€ã«ã®æ¬ ç¹ãç¹å®ã§ããŸãã
ãããã«
ãã®ã¢ããªã±ãŒã·ã§ã³ã®ãããã§ãã»ãã¥ãªãã£ããªã·ãŒã®åŒ±ç¹ã«é¢ããæ å ±ãååŸããã®ã¯éåžžã«é«éã§äŸ¿å©ã§ããã¢ããªã±ãŒã·ã§ã³ã®ã»ããã¢ããã«ã¯å°ãæéããããããããã®ãœãªã¥ãŒã·ã§ã³ã«å€ãã®ã¹ãã«ã¯å¿ èŠãããŸããã ã€ãŸããã»ãã¥ãªãã£èšå®ã«çåããããå€ãã®æéããããã«åæããå¿ èŠãããå Žåãããã¯éåžžã«äŸ¿å©ãªãœãªã¥ãŒã·ã§ã³ã§ãã ãã ããã¢ããªã±ãŒã·ã§ã³ã®ãã¡ã€ãã©ã€ãºãå¿ èŠã§ããããšããŠãŒã¶ãŒã«é¢ããçµ±èšæ å ±ããªãããšãæã䜿çšãããŠããã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ããšããã«åãããã©ãã£ãã¯éãªã©ã確èªããããšã¯éåžžã«èå³æ·±ãããšã§ãã ããã¯æåã®ããŒãžã§ã³ã«ãããªããããã¢ããªã±ãŒã·ã§ã³ã¯æŽæ°ãããé·æã«ããã£ãŠéåžžã«åªããåæãœãªã¥ãŒã·ã§ã³ã«ãªãå¯èœæ§ãé«ããªããŸããããã®ã¢ããªã±ãŒã·ã§ã³ããã°åæã®ã¿ãšèŠãªããšãä»ã®ãœãªã¥ãŒã·ã§ã³ãããã¯ããã«å£ããŸãã åŸç¶ã®èšäºã§ã¯ãSmartEventãšããšã³ãžãã¢ãäœæããã¢ããªã±ãŒã·ã§ã³ãå«ãCheck Pointãã°ãåæããããã®ä»ã®Splunkã¢ããªã±ãŒã·ã§ã³ã®æ©èœãæ€èšããã³æ¯èŒããŸãã
Splunkã䜿çšããŠCheck Pointãã°ãåæããŠããªãå Žåã¯ãéå§ããŸãã SplunkãŸãã¯Check Pointã«é¢ããŠè³ªåãŸãã¯åé¡ãããå Žåã¯ã åœç€Ÿã«åãåãããŠãã ãã ããµããŒãããããŸãã