diff --git a/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3.xif b/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3.xif index 24c3d7896aab..9deba3802784 100644 --- a/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3.xif +++ b/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3.xif @@ -87,6 +87,7 @@ alter Threat_Prevention_Rule_Name = if(cs1Label = "Threat Prevention Rule Name", | alter ipv6src = if(src != null and ipv4src = null, src, null) | alter ipv4dest = if(dst ~= "\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}", dst, null) | alter ipv6dest = if(dst != null and ipv4dest = null, dst, null) +| alter proto = to_string(proto) // Fields Modeling | alter xdm.event.id = loguid, diff --git a/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3_schema.json b/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3_schema.json index b2919969e5b6..5362828f58fa 100644 --- a/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3_schema.json +++ b/Packs/CheckpointFirewall/ModelingRules/CheckpointFirewall_1_3/CheckpointFirewall_1_3_schema.json @@ -301,7 +301,7 @@ "is_array": false }, "proto": { - "type": "string", + "type": "int", "is_array": false }, "cefSeverity": { diff --git a/Packs/CheckpointFirewall/ReleaseNotes/2_3_27.md b/Packs/CheckpointFirewall/ReleaseNotes/2_3_27.md new file mode 100644 index 000000000000..530114177c3c --- /dev/null +++ b/Packs/CheckpointFirewall/ReleaseNotes/2_3_27.md @@ -0,0 +1,6 @@ + +#### Modeling Rules + +##### CheckPoint Firewall Collection + +Updated the Modeling Rule schema for check_point_smartdefense_raw dataset. diff --git a/Packs/CheckpointFirewall/pack_metadata.json b/Packs/CheckpointFirewall/pack_metadata.json index 9fc72d0c4c6a..2f3a16c95c7c 100644 --- a/Packs/CheckpointFirewall/pack_metadata.json +++ b/Packs/CheckpointFirewall/pack_metadata.json @@ -2,7 +2,7 @@ "name": "Check Point Firewall", "description": "Manage Check Point firewall via API", "support": "xsoar", - "currentVersion": "2.3.26", + "currentVersion": "2.3.27", "author": "Cortex XSOAR", "url": "https://www.paloaltonetworks.com/cortex", "email": "",