<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux? in Security</title>
    <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110205#M14358</link>
    <description>&lt;P&gt;Awesome work @Chubbybunny! &lt;EM&gt;thumbs up&lt;/EM&gt; and glad you got your problem solved @felipe_tvrs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2014 23:03:52 GMT</pubDate>
    <dc:creator>ppablo</dc:creator>
    <dc:date>2014-09-05T23:03:52Z</dc:date>
    <item>
      <title>Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110201#M14354</link>
      <description>&lt;P&gt;Hello there guys, I configured the OPSEC LEA client, and everything seems to be fine, but into the "Last Connection" I can see "Not Connected".&lt;BR /&gt;
&lt;BR /&gt;Following are the debug information, I hope somebody can help me, as I already searched a lot.&lt;BR /&gt;
&lt;BR /&gt;Inside the splunkd.log I get the following information:&lt;BR /&gt;
&lt;STRONG&gt;&lt;BR /&gt;Opsec.conf&lt;/STRONG&gt;&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
[root@hostname Splunk_TA_opseclea_linux22]# cat local/opsec.conf&lt;BR /&gt;
[Checkpoint]&lt;BR /&gt;
collect_audit = 0&lt;BR /&gt;
fw_version = 77&lt;BR /&gt;
is_disabled = 0&lt;BR /&gt;
lea_server_auth_port = 18184&lt;BR /&gt;
lea_server_auth_type = sslca&lt;BR /&gt;
lea_server_ip = 172.25.2.174&lt;BR /&gt;
opsec_entity_sic_name = "DN=cp_mgmt,O=bespx2103..8onvkt"&lt;BR /&gt;
opsec_sic_name = "DN=SplunkLEA,O=bespx2103..8onvkt"&lt;BR /&gt;
opsec_sslca_file = ../certs/opsec.p12&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
&lt;/PRE&gt;&lt;BR /&gt;
&lt;STRONG&gt;Splunkd.log:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
09-03-2014 15:38:41.145 -0300 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity Checkpoint" ERROR: failed to create session (Argument is NULL or lacks some data)&lt;BR /&gt;
09-03-2014 15:38:57.807 -0300 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity Checkpoint" ERROR: failed to create session (Argument is NULL or lacks some data)&lt;BR /&gt;
09-03-2014 15:39:14.474 -0300 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity Checkpoint" ERROR: failed to create session (Argument is NULL or lacks some data)&lt;BR /&gt;
09-03-2014 15:39:31.177 -0300 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity Checkpoint" ERROR: failed to create session (Argument is NULL or lacks some data)&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;And this is the output of loggrabber debug mode:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh --configentity Checkpoint --debug-level 3&lt;BR /&gt;
Using Splunk instance: /opt/splunk/, app name Splunk_TA_opseclea_linux22&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
DEBUG: LOGGRABBER configuration file is: /opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/fw1-loggrabber.conf&lt;BR /&gt;
DEBUG: function logging_init_env&lt;BR /&gt;
DEBUG: function open_screen&lt;BR /&gt;
DEBUG: Open connection to screen.&lt;BR /&gt;
DEBUG: Logfilename      : fw.log&lt;BR /&gt;
DEBUG: Record Separator : |&lt;BR /&gt;
DEBUG: Resolve Addresses: No&lt;BR /&gt;
DEBUG: Show Filenames   : No&lt;BR /&gt;
DEBUG: FW1-2000         : No&lt;BR /&gt;
DEBUG: Online-Mode      : No&lt;BR /&gt;
DEBUG: Audit-Log        : No&lt;BR /&gt;
DEBUG: Show Fieldnames  : Yes&lt;BR /&gt;
DEBUG: function get_fw1_logfiles&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint&lt;BR /&gt;
splunk output: QUERYING: 'servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint'&lt;BR /&gt;
xxxx Status: 200.&lt;BR /&gt;
Content:&lt;BR /&gt;
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;
&amp;lt;!--This is to override browser formatting; see server.conf[xxxxServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;&lt;BR /&gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;
&lt;FEED xmlns="/2005/Atom" s="xxxx://dev.splunk.com/ns/rest" opensearch="xxxx://a9.com/-/spec/opensearch/1.1/"&gt;&lt;BR /&gt;
  &lt;TITLE&gt;&lt;/TITLE&gt;&lt;BR /&gt;
  &lt;ID&gt;servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf&lt;/ID&gt;&lt;BR /&gt;
  &lt;UPDATED&gt;2014-09-03T15:41:07-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
  &lt;GENERATOR build="189883" version="6.0.1"&gt;&lt;/GENERATOR&gt;&lt;BR /&gt;
  &lt;AUTHOR&gt;&lt;BR /&gt;
    &lt;NAME&gt;Splunk&lt;/NAME&gt;&lt;BR /&gt;
  &lt;/AUTHOR&gt;&lt;BR /&gt;
  &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/_new" rel="create" /&gt;&lt;BR /&gt;
  &lt;A href="opensearch:totalResults" target="_blank"&gt;opensearch:totalResults&lt;/A&gt;1&lt;A href="/opensearch:totalResults" target="_blank"&gt;/opensearch:totalResults&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:itemsPerPage" target="_blank"&gt;opensearch:itemsPerPage&lt;/A&gt;30&lt;A href="/opensearch:itemsPerPage" target="_blank"&gt;/opensearch:itemsPerPage&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:startIndex" target="_blank"&gt;opensearch:startIndex&lt;/A&gt;0&lt;A href="/opensearch:startIndex" target="_blank"&gt;/opensearch:startIndex&lt;/A&gt;&lt;BR /&gt;
  &lt;MESSAGES&gt;&lt;/MESSAGES&gt;&lt;BR /&gt;
  &lt;ENTRY&gt;&lt;BR /&gt;
    &lt;TITLE&gt;Checkpoint&lt;/TITLE&gt;&lt;BR /&gt;
    &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint&lt;/ID&gt;&lt;BR /&gt;
    &lt;UPDATED&gt;2014-09-03T15:41:07-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint" rel="alternate" /&gt;&lt;BR /&gt;
    &lt;AUTHOR&gt;&lt;BR /&gt;
      &lt;NAME&gt;admin&lt;/NAME&gt;&lt;BR /&gt;
    &lt;/AUTHOR&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint" rel="list" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint" rel="edit" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/Checkpoint" rel="remove" /&gt;&lt;BR /&gt;
    &lt;CONTENT type="text/xml"&gt;&lt;BR /&gt;
      &lt;DICT&gt;&lt;BR /&gt;
        &lt;KEY name="collect_audit"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="disabled"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:acl"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="app"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_change_perms"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_list"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_app"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_global"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_user"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_write"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="modifiable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="owner"&gt;admin&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="perms"&gt;&lt;BR /&gt;
              &lt;DICT&gt;&lt;BR /&gt;
                &lt;KEY name="read"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
                &lt;KEY name="write"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="removable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="sharing"&gt;app&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:appName"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:attributes"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="optionalFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;collect_audit&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;conn_buf_size&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;is_cma&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;is_disabled&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;is_provider&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;lea_server_port&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;no_nagle&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;no_resolve&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;online_mode&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="requiredFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;fw_version&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;lea_server_auth_port&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;lea_server_auth_type&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;lea_server_ip&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;opsec_entity_sic_name&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;opsec_sic_name&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                &lt;ITEM&gt;opsec_sslca_file&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="wildcardFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;/LIST&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:userName"&gt;nobody&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="fw_version"&gt;77&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="is_disabled"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="lea_server_auth_port"&gt;18184&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="lea_server_auth_type"&gt;sslca&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="lea_server_ip"&gt;172.25.2.174&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="opsec_entity_sic_name"&gt;DN=cp_mgmt,O=bespx2103..8onvkt&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="opsec_sic_name"&gt;DN=SplunkLEA,O=bespx2103..8onvkt&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="opsec_sslca_file"&gt;../certs/opsec.p12&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
      &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
    &lt;/KEY&gt;&lt;BR /&gt;
  &lt;/KEY&gt;&lt;BR /&gt;
&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/CONTENT&gt;&lt;/ENTRY&gt;&lt;/FEED&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;-v opsec_sic_name DN=SplunkLEA,O=bespx2103..8onvkt -v opsec_sslca_file ../certs/opsec.p12 -v lea_server ip 172.25.2.174 -v lea_server auth_port 18184 -v lea_server auth_type sslca -v lea_server opsec_entity_sic_name DN=cp_mgmt,O=bespx2103..8onvkt&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Env Configuration:&lt;BR /&gt;
(&lt;BR /&gt;
        :type (opsec_info)&lt;BR /&gt;
        :lea_server (&lt;BR /&gt;
                :opsec_entity_sic_name ("DN=cp_mgmt,O=bespx2103..8onvkt")&lt;BR /&gt;
                :auth_type (sslca)&lt;BR /&gt;
                :auth_port (18184)&lt;BR /&gt;
                :ip (172.25.2.174)&lt;BR /&gt;
        )&lt;BR /&gt;
        :opsec_sslca_file ("../certs/opsec.p12")&lt;BR /&gt;
        :opsec_sic_name ("DN=SplunkLEA,O=bespx2103..8onvkt")&lt;BR /&gt;
)&lt;/P&gt;

&lt;P&gt;[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...opsec_shared_local_path...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...opsec_sic_policy_file...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...opsec_mt...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_init: multithread safety is not initialized&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] cpprng_opsec_initialize: path is not initialized - will initialize&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] cpprng_opsec_initialize: full file name is ops_prng&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] cpprng_opsec_initialize: dev_urandom_poll returned 0&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_file_is_intialized: seed is initialized&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] cpprng_opsec_initialize: seed init for opsec succeeded&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_create: version 5301.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_set_local_names: () names. finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_create: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_set_local_names: (local_sic_name) names. finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_set_local_names: (127.0.0.1) names. finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_set_local_names: ("DN=SplunkLEA,O=bespx2103..8onvkt") names. finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_apply_default_dn: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] get_my_fwca_password: error in name&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] sslcaInitCP_Ex:failed to get password form pkcs12&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_init_sslca: no key holder - symmetric SSLCA not started&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] CkpRegDir: Environment variable CPDIR is not set.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] GenerateGlobalEntry: Unable to get registry path&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_init_sic_id_internal: Added sic id (ctx id = 0)&lt;BR /&gt;
DEBUG: OPSEC LEA conf file is lea.conf&lt;BR /&gt;
DEBUG: Authentication mode has been used.&lt;BR /&gt;
DEBUG: Server-IP     : 172.25.2.174&lt;BR /&gt;
DEBUG: Server-Port     : 18184&lt;BR /&gt;
DEBUG: Authentication type: sslca&lt;BR /&gt;
DEBUG: OPSEC sic certificate file name : ../certs/opsec.p12&lt;BR /&gt;
DEBUG: Server DN (sic name) : DN=cp_mgmt,O=bespx2103..8onvkt&lt;BR /&gt;
DEBUG: OPSEC LEA client DN (sic name) : DN=SplunkLEA,O=bespx2103..8onvkt&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_init_entity_sic: called for the client side&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Configuring entity lea_server&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...conn_buf_size...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...no_nagle...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...port...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_entity_add_sic_rule: adding rules: apply_to: ME, peer: DN=cp_mgmt,O=bespx2103..8onvkt, d_ip: NULL, dport 18184, svc: lea, method: sslca&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_entity_add_sic_rule: adding INBOUND rule&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_entity_add_sic_rule: adding OUTBOUND rule&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_get_comm: creating comm for ent=9b78dc8  peer=9b6ff00 passive=0 key=2 info=0&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] c=0x9b78dc8 s=0x9b6ff00 comm_type=4&lt;/P&gt;

&lt;P&gt;[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Could not find info for ...opsec_client...&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_get_comm: Creating session hash (size=256)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_get_comm: ADDING comm=0x9b7b7e8 to ent=0x9b78dc8 with key=2&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_env_get_context_id_by_peer_sic_name: illegal DN of sic name: DN=cp_mgmt,O=bespx2103..8onvkt&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] OPSEC_SET_ERRNO: err =  4  Argument is NULL or lacks some data (pre =  0)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_sic_connect: failed to get context id for connection&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_get_comm: error in opsec_sic_connect&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] destroying comm 0x9b7b7e8&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Destroying comm 0x9b7b7e8 with 0 active sessions&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] pulling dgtype=ffffffff len=-1 to list=0x9b7b804&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] REMOVING comm=0x9b7b7e8 from ent=0x9b78dc8 with key=2&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Unable to make session&lt;BR /&gt;
ERROR: failed to create session (Argument is NULL or lacks some data)&lt;BR /&gt;
DEBUG: function cleanup_fw1_environment&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Destroying entity 1 with 0 active comms&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_destroy_entity_sic: deleting sic rules for entity 0x9b78dc8&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] Destroying entity 2 with 0 active comms&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_destroy_entity_sic: deleting sic rules for entity 0x9b6ff00&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] IpcUnMapFile: unmapping file (handle=0x9b6f858)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] IpcUnMapFile: unmapping file (handle=0x9b6fbb0)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] IpcUnMapFile: unmapping file (handle=0x9b6fc30)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] IpcUnMapFile: unmapping file (handle=0x9b6fcd0)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] IpcUnMapFile: unmapping file (handle=0x9b6fd50)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] PM_policy_destroy: finished successfully.&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_destroy_sic_id_internal: Destroyed sic id (ctx id=0)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] opsec_env_destroy_sic_id_hash: Destroyed sic id hash&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] fwd_env_destroy: env 0x9b530e8 (alloced = 1)&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] T_env_destroy: env 0x9b530e8&lt;BR /&gt;
[ 19929 4150278960]@hostname.bs.br.bsch[3 Sep 15:41:07] do_fwd_env_destroy:  really destroy 0x9b530e8&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint&lt;BR /&gt;
splunk output: QUERYING: 'xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint'&lt;BR /&gt;
xxxx Status: 200.&lt;BR /&gt;
Content:&lt;BR /&gt;
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;
&amp;lt;!--This is to override browser formatting; see server.conf[xxxxServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;&lt;BR /&gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;
&lt;FEED xmlns="xxxx://www.w3.org/2005/Atom" s="xxxx://dev.splunk.com/ns/rest" opensearch="xxxx://a9.com/-/spec/opensearch/1.1/"&gt;&lt;BR /&gt;
  &lt;TITLE&gt;&lt;/TITLE&gt;&lt;BR /&gt;
  &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health&lt;/ID&gt;&lt;BR /&gt;
  &lt;UPDATED&gt;2014-09-03T15:41:08-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
  &lt;GENERATOR build="189883" version="6.0.1"&gt;&lt;/GENERATOR&gt;&lt;BR /&gt;
  &lt;AUTHOR&gt;&lt;BR /&gt;
    &lt;NAME&gt;Splunk&lt;/NAME&gt;&lt;BR /&gt;
  &lt;/AUTHOR&gt;&lt;BR /&gt;
  &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/_new" rel="create" /&gt;&lt;BR /&gt;
  &lt;A href="opensearch:totalResults" target="_blank"&gt;opensearch:totalResults&lt;/A&gt;1&lt;A href="/opensearch:totalResults" target="_blank"&gt;/opensearch:totalResults&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:itemsPerPage" target="_blank"&gt;opensearch:itemsPerPage&lt;/A&gt;30&lt;A href="/opensearch:itemsPerPage" target="_blank"&gt;/opensearch:itemsPerPage&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:startIndex" target="_blank"&gt;opensearch:startIndex&lt;/A&gt;0&lt;A href="/opensearch:startIndex" target="_blank"&gt;/opensearch:startIndex&lt;/A&gt;&lt;BR /&gt;
  &lt;MESSAGES&gt;&lt;/MESSAGES&gt;&lt;BR /&gt;
  &lt;ENTRY&gt;&lt;BR /&gt;
    &lt;TITLE&gt;Checkpoint&lt;/TITLE&gt;&lt;BR /&gt;
    &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint&lt;/ID&gt;&lt;BR /&gt;
    &lt;UPDATED&gt;2014-09-03T15:41:08-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="alternate" /&gt;&lt;BR /&gt;
    &lt;AUTHOR&gt;&lt;BR /&gt;
      &lt;NAME&gt;admin&lt;/NAME&gt;&lt;BR /&gt;
    &lt;/AUTHOR&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="list" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="edit" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="remove" /&gt;&lt;BR /&gt;
    &lt;CONTENT type="text/xml"&gt;&lt;BR /&gt;
      &lt;DICT&gt;&lt;BR /&gt;
        &lt;KEY name="disabled"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:acl"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="app"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_change_perms"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_list"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_app"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_global"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_user"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_write"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="modifiable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="owner"&gt;admin&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="perms"&gt;&lt;BR /&gt;
              &lt;DICT&gt;&lt;BR /&gt;
                &lt;KEY name="read"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
                &lt;KEY name="write"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="removable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="sharing"&gt;app&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:appName"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:attributes"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="optionalFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;last_connection_timestamp&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="requiredFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;is_connected&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="wildcardFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;/LIST&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:userName"&gt;nobody&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="is_connected"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
      &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
    &lt;/KEY&gt;&lt;BR /&gt;
  &lt;/KEY&gt;&lt;BR /&gt;
&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/CONTENT&gt;&lt;/ENTRY&gt;&lt;/FEED&gt;&lt;/P&gt;

&lt;P&gt;splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/ -post:name Checkpoint -post:is_connected 0 -post:last_connection_timestamp&lt;BR /&gt;
splunk output: QUERYING: 'xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint'&lt;BR /&gt;
xxxx Status: 200.&lt;BR /&gt;
Content:&lt;BR /&gt;
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;
&amp;lt;!--This is to override browser formatting; see server.conf[xxxxServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;&lt;BR /&gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;
&lt;FEED xmlns="xxxx://www.w3.org/2005/Atom" s="xxxx://dev.splunk.com/ns/rest" opensearch="xxxx://a9.com/-/spec/opensearch/1.1/"&gt;&lt;BR /&gt;
  &lt;TITLE&gt;&lt;/TITLE&gt;&lt;BR /&gt;
  &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health&lt;/ID&gt;&lt;BR /&gt;
  &lt;UPDATED&gt;2014-09-03T15:41:08-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
  &lt;GENERATOR build="189883" version="6.0.1"&gt;&lt;/GENERATOR&gt;&lt;BR /&gt;
  &lt;AUTHOR&gt;&lt;BR /&gt;
    &lt;NAME&gt;Splunk&lt;/NAME&gt;&lt;BR /&gt;
  &lt;/AUTHOR&gt;&lt;BR /&gt;
  &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/_new" rel="create" /&gt;&lt;BR /&gt;
  &lt;A href="opensearch:totalResults" target="_blank"&gt;opensearch:totalResults&lt;/A&gt;1&lt;A href="/opensearch:totalResults" target="_blank"&gt;/opensearch:totalResults&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:itemsPerPage" target="_blank"&gt;opensearch:itemsPerPage&lt;/A&gt;30&lt;A href="/opensearch:itemsPerPage" target="_blank"&gt;/opensearch:itemsPerPage&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:startIndex" target="_blank"&gt;opensearch:startIndex&lt;/A&gt;0&lt;A href="/opensearch:startIndex" target="_blank"&gt;/opensearch:startIndex&lt;/A&gt;&lt;BR /&gt;
  &lt;MESSAGES&gt;&lt;/MESSAGES&gt;&lt;BR /&gt;
  &lt;ENTRY&gt;&lt;BR /&gt;
    &lt;TITLE&gt;Checkpoint&lt;/TITLE&gt;&lt;BR /&gt;
    &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint&lt;/ID&gt;&lt;BR /&gt;
    &lt;UPDATED&gt;2014-09-03T15:41:08-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="alternate" /&gt;&lt;BR /&gt;
    &lt;AUTHOR&gt;&lt;BR /&gt;
      &lt;NAME&gt;admin&lt;/NAME&gt;&lt;BR /&gt;
    &lt;/AUTHOR&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="list" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="edit" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="remove" /&gt;&lt;BR /&gt;
    &lt;CONTENT type="text/xml"&gt;&lt;BR /&gt;
      &lt;DICT&gt;&lt;BR /&gt;
        &lt;KEY name="disabled"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:acl"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="app"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_change_perms"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_list"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_app"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_global"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_user"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_write"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="modifiable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="owner"&gt;admin&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="perms"&gt;&lt;BR /&gt;
              &lt;DICT&gt;&lt;BR /&gt;
                &lt;KEY name="read"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
                &lt;KEY name="write"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="removable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="sharing"&gt;app&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:appName"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:attributes"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="optionalFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;last_connection_timestamp&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="requiredFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;BR /&gt;
                &lt;ITEM&gt;is_connected&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="wildcardFields"&gt;&lt;BR /&gt;
              &lt;LIST&gt;&lt;/LIST&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:userName"&gt;nobody&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="is_connected"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
      &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
    &lt;/KEY&gt;&lt;BR /&gt;
  &lt;/KEY&gt;&lt;BR /&gt;
&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/CONTENT&gt;&lt;/ENTRY&gt;&lt;/FEED&gt;&lt;/P&gt;

&lt;P&gt;QUERYING: 'xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/'&lt;BR /&gt;
xxxx Status: 201.&lt;BR /&gt;
Content:&lt;BR /&gt;
&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;
&amp;lt;!--This is to override browser formatting; see server.conf[xxxxServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;&lt;BR /&gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;&lt;BR /&gt;
&lt;FEED xmlns="xxxx://www.w3.org/2005/Atom" s="xxxx://dev.splunk.com/ns/rest" opensearch="xxxx://a9.com/-/spec/opensearch/1.1/"&gt;&lt;BR /&gt;
  &lt;TITLE&gt;&lt;/TITLE&gt;&lt;BR /&gt;
  &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health&lt;/ID&gt;&lt;BR /&gt;
  &lt;UPDATED&gt;2014-09-03T15:41:09-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
  &lt;GENERATOR build="189883" version="6.0.1"&gt;&lt;/GENERATOR&gt;&lt;BR /&gt;
  &lt;AUTHOR&gt;&lt;BR /&gt;
    &lt;NAME&gt;Splunk&lt;/NAME&gt;&lt;BR /&gt;
  &lt;/AUTHOR&gt;&lt;BR /&gt;
  &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/_new" rel="create" /&gt;&lt;BR /&gt;
  &lt;A href="opensearch:totalResults" target="_blank"&gt;opensearch:totalResults&lt;/A&gt;1&lt;A href="/opensearch:totalResults" target="_blank"&gt;/opensearch:totalResults&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:itemsPerPage" target="_blank"&gt;opensearch:itemsPerPage&lt;/A&gt;30&lt;A href="/opensearch:itemsPerPage" target="_blank"&gt;/opensearch:itemsPerPage&lt;/A&gt;&lt;BR /&gt;
  &lt;A href="opensearch:startIndex" target="_blank"&gt;opensearch:startIndex&lt;/A&gt;0&lt;A href="/opensearch:startIndex" target="_blank"&gt;/opensearch:startIndex&lt;/A&gt;&lt;BR /&gt;
  &lt;MESSAGES&gt;&lt;/MESSAGES&gt;&lt;BR /&gt;
  &lt;ENTRY&gt;&lt;BR /&gt;
    &lt;TITLE&gt;Checkpoint&lt;/TITLE&gt;&lt;BR /&gt;
    &lt;ID&gt;xxxxs://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint&lt;/ID&gt;&lt;BR /&gt;
    &lt;UPDATED&gt;2014-09-03T15:41:09-03:00&lt;/UPDATED&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="alternate" /&gt;&lt;BR /&gt;
    &lt;AUTHOR&gt;&lt;BR /&gt;
      &lt;NAME&gt;admin&lt;/NAME&gt;&lt;BR /&gt;
    &lt;/AUTHOR&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="list" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="edit" /&gt;&lt;BR /&gt;
    &lt;LINK href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/entity_health/Checkpoint" rel="remove" /&gt;&lt;BR /&gt;
    &lt;CONTENT type="text/xml"&gt;&lt;BR /&gt;
      &lt;DICT&gt;&lt;BR /&gt;
        &lt;KEY name="disabled"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:acl"&gt;&lt;BR /&gt;
          &lt;DICT&gt;&lt;BR /&gt;
            &lt;KEY name="app"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_change_perms"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_list"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_app"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_global"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_share_user"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="can_write"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="modifiable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="owner"&gt;admin&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="perms"&gt;&lt;BR /&gt;
              &lt;DICT&gt;&lt;BR /&gt;
                &lt;KEY name="read"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
                &lt;KEY name="write"&gt;&lt;BR /&gt;
                  &lt;LIST&gt;&lt;BR /&gt;
                    &lt;ITEM&gt;admin&lt;A href="/s:item" target="_blank"&gt;/s:item&lt;/A&gt;&lt;BR /&gt;
                  &lt;A href="/s:list" target="_blank"&gt;/s:list&lt;/A&gt;&lt;BR /&gt;
                &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
              &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
            &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="removable"&gt;1&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
            &lt;KEY name="sharing"&gt;app&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
          &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
        &lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:appName"&gt;Splunk_TA_opseclea_linux22&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:attributes"&gt;{'wildcardFields': ['.*'], 'optionalFields': [], 'requiredFields': []}&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="eai:userName"&gt;nobody&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
        &lt;KEY name="is_connected"&gt;0&lt;A href="/s:key" target="_blank"&gt;/s:key&lt;/A&gt;&lt;BR /&gt;
      &lt;A href="/s:dict" target="_blank"&gt;/s:dict&lt;/A&gt;&lt;BR /&gt;
    &lt;/KEY&gt;&lt;BR /&gt;
  &lt;/KEY&gt;&lt;BR /&gt;
&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/ITEM&gt;&lt;/LIST&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/KEY&gt;&lt;/KEY&gt;&lt;/DICT&gt;&lt;/CONTENT&gt;&lt;/ENTRY&gt;&lt;/FEED&gt;&lt;/P&gt;

&lt;P&gt;DEBUG: function exit_loggrabber&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;BR /&gt;
DEBUG: function free_afield_arrays&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;BR /&gt;
DEBUG: function free_afield_arrays&lt;BR /&gt;
&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110201#M14354</guid>
      <dc:creator>felipe_tvrs</dc:creator>
      <dc:date>2020-09-28T17:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110202#M14355</link>
      <description>&lt;P&gt;Possible condition:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [ 19929 4150278960]@bsbrsp4252.bs.br.bsch[3 Sep 15:41:07] opsec_env_get_context_id_by_peer_sic_name: illegal DN of sic name: DN=cp_mgmt,O=bespx2103..8onvkt
[ 19929 4150278960]@bsbrsp4252.bs.br.bsch[3 Sep 15:41:07] OPSEC_SET_ERRNO: err =  4  Argument is NULL or lacks some data (pre =  0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The configured &lt;CODE&gt;opsec_entity_sic_name&lt;/CODE&gt; is incorrect. &lt;BR /&gt;
To verify  the Entity SIC Name:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Open GuiDBedit (the Check Point Database Tool).&lt;/LI&gt;
&lt;LI&gt;Go to Tables &amp;gt; Network Objects &amp;gt; network object (at left).
A list of network objects opens (at right).&lt;/LI&gt;
&lt;LI&gt;Click the network object (for example, opsec-fw1-r7540) in the list.
A list of object attributes appears (at bottom).&lt;/LI&gt;
&lt;LI&gt;Scroll down the list to find the sic_name field (near the end of the list), or search for the sic_name field. The sic name will look similar to this:
CN=cn=cp_mgmt,o=opsec-p1-r7540-test-env-domain1_management_server..pj7ux4.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110202#M14355</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2020-09-28T17:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110203#M14356</link>
      <description>&lt;P&gt;Hello There &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/2058"&gt;@Chubbybunny&lt;/a&gt;!&lt;BR /&gt;
Thank you, I could get the opsec_entity_sic_name (CN=cp_mgmt_FW-01,O=bespx2103..8onvkt), but when trying to connect, I received this: &lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
SIC ERROR 111 - SIC Error for lea: Peer sent wrong DN: cn=cp_mgmt,o=mds-01..tng23o&lt;BR /&gt;
&lt;/PRE&gt;&lt;BR /&gt;
As if the entity sic name used was wrong and, if I try with this new sic_name, the problem turns to a third one:&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
SIC ERROR 147 - SIC Error for lea: Authentication error&lt;BR /&gt;
&lt;/PRE&gt;&lt;BR /&gt;
I'm doing some searches to see if I get any advances.&lt;/P&gt;

&lt;P&gt;Thank you so far!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110203#M14356</guid>
      <dc:creator>felipe_tvrs</dc:creator>
      <dc:date>2020-09-28T17:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110204#M14357</link>
      <description>&lt;P&gt;Hello there @Chubbybunny. I finally managed to put it to work!&lt;BR /&gt;
I needed to configure to change the "DN" from the SIC name to "CN", and it finally worked! Now I'm with tons of events to work on filtering.&lt;BR /&gt;
Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2014 17:54:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110204#M14357</guid>
      <dc:creator>felipe_tvrs</dc:creator>
      <dc:date>2014-09-04T17:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110205#M14358</link>
      <description>&lt;P&gt;Awesome work @Chubbybunny! &lt;EM&gt;thumbs up&lt;/EM&gt; and glad you got your problem solved @felipe_tvrs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 23:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110205#M14358</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-09-05T23:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting connection errors after configuring Add-on for Check Point OPSEC LEA Linux?</title>
      <link>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110206#M14359</link>
      <description>&lt;P&gt;Hello - I am having this issue as well.  Can you please clarify what you mean be changing the DN from the SIC name to "CN"?   ie can you give an example of what you changed?  Thanks &lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 15:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Why-am-I-getting-connection-errors-after-configuring-Add-on-for/m-p/110206#M14359</guid>
      <dc:creator>jareddavis1</dc:creator>
      <dc:date>2018-08-22T15:10:52Z</dc:date>
    </item>
  </channel>
</rss>

