<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OPSEC App indexing much more than expected in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-App-indexing-much-more-than-expected/m-p/217625#M23625</link>
    <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;so we installed the OPSEC App yesterday (took about 2 hours) and now we get Logs - a LOT of logs. &lt;BR /&gt;
Our firewall Team expected around 25 Gig per day, now at 8am we are at around 40 Gig.&lt;/P&gt;

&lt;P&gt;Now I was wondering if maybe the configuration of opsec app is somehow incorrect and that maybe data is indexed multiple times or something the like. I did few very short tests to find duplicates (just searched for the raw test of an event) but could not find any. &lt;/P&gt;

&lt;P&gt;Are there any known configuration mistakes that might cause such that much data to be indexed. During the configuration we did had to create/delete/re-create several connections and trust relations, but now we only have the connections that we actually need and want. &lt;/P&gt;

&lt;P&gt;What I am a little bit worried about is the following configuration in the opsec-log-status.conf file. I see multiple stanzas for the same data-source (clm-data-1) but only for the last one the "last_rec_pos" variable is increased automatically. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[1466632741@clm-data-1]
fileid = 1466632741
filename = fw.log
last_rec_pos = 23801843

[1466644651@clm-data-1]
fileid = 1466644651
filename = fw.log
last_rec_pos = 23725430

[1466655679@clm-data-1]
fileid = 1466655679
filename = fw.log
last_rec_pos = 23407048

[1466661952@clm-data-1]
fileid = 1466661952
filename = fw.log
last_rec_pos = 1710000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or are there any features on how to reduce the amount of data indexed by the opsec app. We could deactivate VPN and Audit Logging but that's only around 1% of all logs. &lt;/P&gt;

&lt;P&gt;Thank you !&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:59:53 GMT</pubDate>
    <dc:creator>pinVie</dc:creator>
    <dc:date>2020-09-29T09:59:53Z</dc:date>
    <item>
      <title>OPSEC App indexing much more than expected</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-App-indexing-much-more-than-expected/m-p/217625#M23625</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;so we installed the OPSEC App yesterday (took about 2 hours) and now we get Logs - a LOT of logs. &lt;BR /&gt;
Our firewall Team expected around 25 Gig per day, now at 8am we are at around 40 Gig.&lt;/P&gt;

&lt;P&gt;Now I was wondering if maybe the configuration of opsec app is somehow incorrect and that maybe data is indexed multiple times or something the like. I did few very short tests to find duplicates (just searched for the raw test of an event) but could not find any. &lt;/P&gt;

&lt;P&gt;Are there any known configuration mistakes that might cause such that much data to be indexed. During the configuration we did had to create/delete/re-create several connections and trust relations, but now we only have the connections that we actually need and want. &lt;/P&gt;

&lt;P&gt;What I am a little bit worried about is the following configuration in the opsec-log-status.conf file. I see multiple stanzas for the same data-source (clm-data-1) but only for the last one the "last_rec_pos" variable is increased automatically. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[1466632741@clm-data-1]
fileid = 1466632741
filename = fw.log
last_rec_pos = 23801843

[1466644651@clm-data-1]
fileid = 1466644651
filename = fw.log
last_rec_pos = 23725430

[1466655679@clm-data-1]
fileid = 1466655679
filename = fw.log
last_rec_pos = 23407048

[1466661952@clm-data-1]
fileid = 1466661952
filename = fw.log
last_rec_pos = 1710000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or are there any features on how to reduce the amount of data indexed by the opsec app. We could deactivate VPN and Audit Logging but that's only around 1% of all logs. &lt;/P&gt;

&lt;P&gt;Thank you !&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-App-indexing-much-more-than-expected/m-p/217625#M23625</guid>
      <dc:creator>pinVie</dc:creator>
      <dc:date>2020-09-29T09:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC App indexing much more than expected</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-App-indexing-much-more-than-expected/m-p/217626#M23626</link>
      <description>&lt;P&gt;Are you using &lt;CODE&gt;Splunk_TA_opseclea_linux22&lt;/CODE&gt; (aka version 3.1) or &lt;CODE&gt;Splunk_TA_checkpoint-opseclea&lt;/CODE&gt; (aka version 4.0)?&lt;/P&gt;

&lt;P&gt;If you're using 3.1, are you passing unique values for configentity?  e.g.: audit, vpn, ips, etc?&lt;/P&gt;

&lt;P&gt;You might also be pulling historical data, as well as current.  If that's the case then the data volume should settle down after your initial import.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 18:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-App-indexing-much-more-than-expected/m-p/217626#M23626</guid>
      <dc:creator>jamesarmitage</dc:creator>
      <dc:date>2016-06-23T18:09:46Z</dc:date>
    </item>
  </channel>
</rss>

