<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling other sourcetype inputs from OPSEC LEA in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217797#M23697</link>
    <description>&lt;P&gt;Some further testing: There's definitely a difference in how the old Check Point app and the new one pulled data data from the OPSEC application. I got annoyed by the fact that the default interval was '3600' on the new app and I kept changing it to '30' as per the default on the old app.&lt;/P&gt;

&lt;P&gt;This quickly led to MANY lea_loggrabber instances running concurrently and I suspect that is what stopped the data flow.&lt;/P&gt;

&lt;P&gt;I'm now back on the default interval of 3600 and things seem to be more stable... whether they'll stay that way after an hour is something I'll be reporting back on later...&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2016 12:59:29 GMT</pubDate>
    <dc:creator>tiny3001</dc:creator>
    <dc:date>2016-06-24T12:59:29Z</dc:date>
    <item>
      <title>Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217793#M23693</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;

&lt;P&gt;We have a client that recently added the new Anti-Bot, Anti-Virus and Threat Emulation blades to their Checkpoint installation.&lt;/P&gt;

&lt;P&gt;We are already gathering their Firewall and SmartDefense logs via the older Checkpoint OPSEC LEA app. I've now migrated those inputs to the new app and everything seems to be up and running, however, can't seem to create inputs for the &lt;CODE&gt;opsec:anti_malware&lt;/CODE&gt; and &lt;CODE&gt;opsec:anti_virus&lt;/CODE&gt; sourcetypes. The drop-down list on the "Create input" screen does not allow checking for that.&lt;/P&gt;

&lt;P&gt;Is there a step that I'm missing? Could it be that we need the client to change something on the Checkpoint Firewall?&lt;/P&gt;

&lt;P&gt;I've even tried overriding the &lt;CODE&gt;data&lt;/CODE&gt; field in &lt;CODE&gt;opseclea_inputs.conf&lt;/CODE&gt; and tried values like &lt;CODE&gt;anti_malware&lt;/CODE&gt; and &lt;CODE&gt;anti_virus&lt;/CODE&gt;. The inputs screen just shows &lt;CODE&gt;undefined&lt;/CODE&gt; for the data field if I do that.&lt;/P&gt;

&lt;P&gt;Please help?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 10:35:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217793#M23693</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2016-06-23T10:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217794#M23694</link>
      <description>&lt;P&gt;The &lt;CODE&gt;opsec:antimalware&lt;/CODE&gt; and &lt;CODE&gt;opsec:antivirus&lt;/CODE&gt; events should be pulled if you use the Non-Audit input.  &lt;/P&gt;

&lt;P&gt;I'm having trouble with that setting, but have managed to retrieve some of those events that way.  I find that my data collection is hanging after an initial connection.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 17:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217794#M23694</guid>
      <dc:creator>jamesarmitage</dc:creator>
      <dc:date>2016-06-23T17:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217795#M23695</link>
      <description>&lt;P&gt;Thank you. It doesn't seem intuitive at all, but I guess at some stage I could have just tried Non-Audit to see what it does.&lt;/P&gt;

&lt;P&gt;I am also experiencing the data collection dying after a while.&lt;/P&gt;

&lt;P&gt;Finally, there also seems to be an issue with the &lt;CODE&gt;opsec:anti_bot&lt;/CODE&gt; sourcetype incorrectly going to &lt;CODE&gt;opsec:anti_malware&lt;/CODE&gt; because of this bug posted on Check Points' website:&lt;BR /&gt;
&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111887"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111887&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2016 12:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217795#M23695</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2016-06-24T12:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217796#M23696</link>
      <description>&lt;P&gt;I've also now tested both online mode and offline mode to see if it makes a difference. I get data flowing in for about 5 minutes and then it dies. Did not have this old issue with the older Check Point app.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2016 12:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217796#M23696</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2016-06-24T12:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217797#M23697</link>
      <description>&lt;P&gt;Some further testing: There's definitely a difference in how the old Check Point app and the new one pulled data data from the OPSEC application. I got annoyed by the fact that the default interval was '3600' on the new app and I kept changing it to '30' as per the default on the old app.&lt;/P&gt;

&lt;P&gt;This quickly led to MANY lea_loggrabber instances running concurrently and I suspect that is what stopped the data flow.&lt;/P&gt;

&lt;P&gt;I'm now back on the default interval of 3600 and things seem to be more stable... whether they'll stay that way after an hour is something I'll be reporting back on later...&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2016 12:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217797#M23697</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2016-06-24T12:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217798#M23698</link>
      <description>&lt;P&gt;FYI: They didn't stay stable&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 03:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217798#M23698</guid>
      <dc:creator>tiny3001</dc:creator>
      <dc:date>2016-06-27T03:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling other sourcetype inputs from OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217799#M23699</link>
      <description>&lt;P&gt;I've noticed the exact same issue as you.  I'm just about to open another question thread, with some additional background info that I've found.  I believe it's a bug in the data-handling that only comes up with the Non-Audit setting.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2016 16:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Enabling-other-sourcetype-inputs-from-OPSEC-LEA/m-p/217799#M23699</guid>
      <dc:creator>jamesarmitage</dc:creator>
      <dc:date>2016-06-27T16:59:30Z</dc:date>
    </item>
  </channel>
</rss>

