<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk reporting invalid key stanza for the &amp;quot;management_server_ip&amp;quot; value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300330#M35847</link>
    <description>&lt;P&gt;It is telling you that line #9 ( &lt;CODE&gt;management_server_ip = 192.168.0.10&lt;/CODE&gt; ) is malformed.  Usually this means that you have spelled the key wrong (case matters) or that the line is garbage/unnecessary/deprecated.  That is not listed in the docs so REMOVE IT:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2017 14:17:17 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-04-03T14:17:17Z</dc:date>
    <item>
      <title>Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300327#M35844</link>
      <description>&lt;P&gt;I've configured the app with the proper values including the management server IP address but when starting Splunk, the conf file check shows the management server IP is, for some reason, invalid.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Invalid key in stanza [CHECKPOINT_MGR] in /opt/splunk/etc/apps/Splunk_TA_checkpoint-opseclea/local/opseclea_connection.conf, line 9: management_server_ip  (value:  192.168.0.10).&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Below is the config file we are using.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[root@splunk local]# more opseclea_connection.conf&lt;BR /&gt;
[CHECKPOINT_MGR] &lt;BR /&gt;
cert_name = CHECKPOINT_MGR_4189510259.p12&lt;BR /&gt;
fw_version = R77 &lt;BR /&gt;
lea_app_name = SplunkLEA &lt;BR /&gt;
lea_server_auth_port = 18184&lt;BR /&gt;
lea_server_auth_type = sslca&lt;BR /&gt;
lea_server_ip = 192.168.0.10&lt;BR /&gt;
lea_server_type = primary&lt;BR /&gt;
management_server_ip = 192.168.0.10&lt;BR /&gt;
opsec_entity_sic_name = CN=cp_mgmt,O=CHECKPOINT_MGR.wrbdb6&lt;BR /&gt;
opsec_sic_name = CN=SplunkLEA,O=CHECKPOINT_MGR.wrbdb6&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300327#M35844</guid>
      <dc:creator>jmaple</dc:creator>
      <dc:date>2020-09-29T13:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300328#M35845</link>
      <description>&lt;P&gt;I have NEVER done either of these things that you are doing:&lt;BR /&gt;
1: put anything on the same line as the stanza header (i.e. the first line should be &lt;CODE&gt;[CHECKPOINT_MGR]&lt;/CODE&gt; and the second line should be &lt;CODE&gt;cert_name = CHECKPOINT_MGR_4189510259.p12&lt;/CODE&gt;).&lt;BR /&gt;
2: Split my KVP across lines (e.g the last 2 lines should actually be 1 line that reads &lt;CODE&gt;opsec_sic_name =&lt;BR /&gt;
CN=SplunkLEA,O=CHECKPOINT_MGR.wrbdb6&lt;/CODE&gt;).&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 13:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300328#M35845</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-03T13:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300329#M35846</link>
      <description>&lt;P&gt;Apologies for the formatting issues. I've fixed the lines to read how they are in the actual file.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 13:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300329#M35846</guid>
      <dc:creator>jmaple</dc:creator>
      <dc:date>2017-04-03T13:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300330#M35847</link>
      <description>&lt;P&gt;It is telling you that line #9 ( &lt;CODE&gt;management_server_ip = 192.168.0.10&lt;/CODE&gt; ) is malformed.  Usually this means that you have spelled the key wrong (case matters) or that the line is garbage/unnecessary/deprecated.  That is not listed in the docs so REMOVE IT:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 14:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300330#M35847</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-03T14:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300331#M35848</link>
      <description>&lt;P&gt;So it looks like the error was related to it not existing however the app itself requires that value when you configure the connection using the GUI. Might need an update to not require it/remove it?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 16:12:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300331#M35848</guid>
      <dc:creator>jmaple</dc:creator>
      <dc:date>2017-04-03T16:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk reporting invalid key stanza for the "management_server_ip" value in the conf file check of the Splunk Add-on for Check Point OPSEC LEA?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300332#M35849</link>
      <description>&lt;P&gt;I'm getting the same error, though everything seems to work as expected. The GUI actually populates the config file with the management_server_ip value that Splunk doesn't like.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-reporting-invalid-key-stanza-for-the-quot/m-p/300332#M35849</guid>
      <dc:creator>Kieffer87</dc:creator>
      <dc:date>2020-09-29T13:27:11Z</dc:date>
    </item>
  </channel>
</rss>

