<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266379#M30833</link>
    <description>&lt;P&gt;I ended up installing the OPSEC add-on in a Heavy Forwarder running one of the supported Linux flavours.&lt;BR /&gt;
If I were you I would either try that or use a Standalone Search Head.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2016 09:14:35 GMT</pubDate>
    <dc:creator>javiergn</dc:creator>
    <dc:date>2016-07-20T09:14:35Z</dc:date>
    <item>
      <title>How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266378#M30832</link>
      <description>&lt;P&gt;Hi fellow splunkers, &lt;/P&gt;

&lt;P&gt;I have a question on the installation process of the Splunk Add-on for Checkpoint OPSEC LEA.&lt;BR /&gt;
I have read the following document:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Install"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Install&lt;/A&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;The following section concerns me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Distributed deployment feature  Supported
Search Head Clusters               No
Indexer Clusters                   Yes
Deployment Server                 No  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;Should this tell me installation over a deployer for the search head cluster is not possible?&lt;BR /&gt;
If yes, should I then manually install this app on every search head in the cluster?&lt;/P&gt;

&lt;P&gt;Best regards, &lt;BR /&gt;
pyro_wood&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 09:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266378#M30832</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2016-07-20T09:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266379#M30833</link>
      <description>&lt;P&gt;I ended up installing the OPSEC add-on in a Heavy Forwarder running one of the supported Linux flavours.&lt;BR /&gt;
If I were you I would either try that or use a Standalone Search Head.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 09:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266379#M30833</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-07-20T09:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266380#M30834</link>
      <description>&lt;P&gt;Thanks for your quick reply javiergn,&lt;BR /&gt;
so you never installed this Add-on on a Search-Head?&lt;/P&gt;

&lt;P&gt;What is the value I would get installing it on the SH?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 10:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266380#M30834</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2016-07-20T10:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266381#M30835</link>
      <description>&lt;P&gt;You can install it on a Search Head, provided is not part of a cluster.&lt;BR /&gt;
But I always try to isolate collection layer to Forwarders only (Heavy or Universal) whereas Search Heads are just for searching purposes.&lt;/P&gt;

&lt;P&gt;If the OPSEC app causes any impact on your search head or you need to restart it for whatever reason, you are bringing your search head down. Whereas if you have it on a HF, it's just the HF what is impacted.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 10:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266381#M30835</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-07-20T10:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266382#M30836</link>
      <description>&lt;P&gt;Well... your approach on this actually makes a lot of sense. I will try to set it up on a HF. &lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 10:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266382#M30836</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2016-07-20T10:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266383#M30837</link>
      <description>&lt;P&gt;Hi javiergn, I am also trying to install the latest version of OPSEC on a HF but I am not seeing any events being forwarded to the Indexer. &lt;BR /&gt;
I am assuming you had to add an outputs.conf (standard configuration, forward events to a port and on the indexer listen in on the port). &lt;BR /&gt;
1) Are there any other changes you had to make to the ? &lt;BR /&gt;
    opseclea_connection.conf&lt;BR /&gt;
    opseclea_inputs.conf&lt;BR /&gt;
2) Did you make any changes on the indexer? (i am assuming you have the app installed on the indexer)&lt;/P&gt;

&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266383#M30837</guid>
      <dc:creator>hassanali</dc:creator>
      <dc:date>2020-09-29T11:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to install the Splunk Add-on for Checkpoint OPSEC LEA in a search head clustering environment?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266384#M30838</link>
      <description>&lt;P&gt;1) &lt;BR /&gt;
Did you configure the OPSEC LEA object in your CheckPoint manager?&lt;BR /&gt;
You then need to establish a session with a one-time password between your manager and your HF.&lt;/P&gt;

&lt;P&gt;It's all here: &lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Setup"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Setup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;2) &lt;BR /&gt;
No I did not make any changes on the indexer as the parsing provided by the app was good enough.&lt;/P&gt;

&lt;P&gt;If you can't see any logs flowing take a look at the troubleshooting section first: &lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Troubleshoot"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Troubleshoot&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If that doesn't help, raise a new question with the specific details of your problem as you will get a much wider audience that way. Please keep in mind this post was referred to version 3 and not 4 of the OPSEC LEA app.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
J&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 09:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-install-the-Splunk-Add-on-for-Checkpoint-OPSEC-LEA-in-a/m-p/266384#M30838</guid>
      <dc:creator>javiergn</dc:creator>
      <dc:date>2016-12-06T09:13:35Z</dc:date>
    </item>
  </channel>
</rss>

