<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure the Splunk Add-on for Check Point OPSEC LEA in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346832#M66993</link>
    <description>&lt;P&gt;hi thanks, but i know have the next issue jejeje .. when i create a input&lt;/P&gt;

&lt;P&gt;ERROR: Session end reason: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea&lt;/P&gt;

&lt;P&gt;do you know what is going on ?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Aug 2018 20:36:01 GMT</pubDate>
    <dc:creator>evinasco</dc:creator>
    <dc:date>2018-08-15T20:36:01Z</dc:date>
    <item>
      <title>Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346824#M66985</link>
      <description>&lt;P&gt;Hi everyone,&lt;BR /&gt;
I'm need to Configure the Splunk Add-on for Check Point OPSEC LEA but i has faced some problems. I can't add new connection.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4008i25D6294B44F65A29/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;192.168.20.1 is IP of Checkpoint FW&lt;BR /&gt;
192.168.20.30 is IP of Splunk&lt;/P&gt;

&lt;P&gt;I has pull the certifiacte success from Checkpoint but  i can't select it on SIC Certificate. I can't Reuse Existing SIC Certificate option.&lt;/P&gt;

&lt;P&gt;And in Checkpoint SmartConsole. I can't see where to check SIC status.&lt;/P&gt;

&lt;P&gt;Please help,&lt;BR /&gt;
Quang&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2017 04:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346824#M66985</guid>
      <dc:creator>lnhquang1993</dc:creator>
      <dc:date>2017-12-16T04:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346825#M66986</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Looking at the &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Setup2"&gt;doco&lt;/A&gt; Mgt Server IP isn't that of the Splunk server but of the Check Point Mgt Server, if it is a standalone environment (#6.2 on doco page).&lt;/P&gt;

&lt;P&gt;I would suggest confirming all of the steps in the doco setup, then if it still isn't working provide here:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Which step you believe it failed upon&lt;/LI&gt;
&lt;LI&gt;The stderr lines within the splunkd.log referenced in the error message&lt;/LI&gt;
&lt;LI&gt;Check the ../certs/ folder within the app - and the permissions for the folder/files&lt;/LI&gt;
&lt;LI&gt;Output from the web_service.log &lt;EM&gt;reference the troubleshoot section of the linked doco page&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 18 Dec 2017 01:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346825#M66986</guid>
      <dc:creator>lmaclean</dc:creator>
      <dc:date>2017-12-18T01:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346826#M66987</link>
      <description>&lt;P&gt;Hi lmaclean,&lt;BR /&gt;
Thanks for your help. And yes i recognize my fault. It a standalone enviroment so both Log Server IP and Mgt Server IP is the same - 192.168.20.1 right ? But i still get error :&lt;BR /&gt;
&lt;EM&gt;External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - The referred entity does not exist in the Certificate Authority. Make sure you have provided the right application name and one-time password'. See splunkd.log for stderr output.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I pretty sure that i has type the right application name and one-time password.&lt;BR /&gt;
Here is the application that i create on CP :&lt;BR /&gt;
&lt;STRONG&gt;name = splunk-lea       OTP = 123&lt;/STRONG&gt;&lt;BR /&gt;
and i use it to pull-cert from CP to Splunk :&lt;BR /&gt;
&lt;STRONG&gt;./pull-cert.sh 192.168.20.1 splunk-lea 123 splunk.pl2&lt;/STRONG&gt;&lt;BR /&gt;
and out show that Certifiacte success written to ../certs/splunk.pl2.&lt;/P&gt;

&lt;P&gt;so the application name and OTP can't be wrong right ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 02:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346826#M66987</guid>
      <dc:creator>lnhquang1993</dc:creator>
      <dc:date>2017-12-18T02:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346827#M66988</link>
      <description>&lt;P&gt;Might be worth looking at the opseclea_connection.conf file in the ../local/ folder and seeing if the settings match what you have configured in Check Point.  &lt;/P&gt;

&lt;P&gt;Also remember they are case sensitive; password cannot contain certain special characters; reapply the password in Check Point after each failed attempt incase after the first failed try it blocks it out; and that all the other settings in the file match your environment as well.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Configureinputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Edit: Oh and on the end of the cert script it is a number &lt;STRONG&gt;one&lt;/STRONG&gt; (1) right not an &lt;STRONG&gt;l&lt;/STRONG&gt; (L) that you are running??&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 03:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346827#M66988</guid>
      <dc:creator>lmaclean</dc:creator>
      <dc:date>2017-12-18T03:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346828#M66989</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Have you resolved the issue ? currently i'm facing the same issue. &lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 01:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346828#M66989</guid>
      <dc:creator>kalaiarasu</dc:creator>
      <dc:date>2018-05-21T01:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346829#M66990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I was facing the same issue. I solved this by giving proper permission to "$SPLUK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/" folder. Make sure your application folder is having proper permission and should have "$SPLUK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/local/" folder.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346829#M66990</guid>
      <dc:creator>ektasiwani</dc:creator>
      <dc:date>2020-09-29T20:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346830#M66991</link>
      <description>&lt;P&gt;what kind of permissions does it need? 777? in linux&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 16:47:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346830#M66991</guid>
      <dc:creator>evinasco</dc:creator>
      <dc:date>2018-08-15T16:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346831#M66992</link>
      <description>&lt;P&gt;Yes. You need to give 777 permission.&lt;/P&gt;

&lt;P&gt;If giving permission will not solve your issue please follow steps mentioned in below link. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/614787/splunk-check-point-lea-opsec-error-fatal-error-gli.html"&gt;https://answers.splunk.com/answers/614787/splunk-check-point-lea-opsec-error-fatal-error-gli.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 16:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346831#M66992</guid>
      <dc:creator>ektasiwani</dc:creator>
      <dc:date>2018-08-15T16:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346832#M66993</link>
      <description>&lt;P&gt;hi thanks, but i know have the next issue jejeje .. when i create a input&lt;/P&gt;

&lt;P&gt;ERROR: Session end reason: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea&lt;/P&gt;

&lt;P&gt;do you know what is going on ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 20:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346832#M66993</guid>
      <dc:creator>evinasco</dc:creator>
      <dc:date>2018-08-15T20:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346833#M66994</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;This issue is because OPSEC side started to use sha256 and updated its SDK.&lt;BR /&gt;
Download file from &lt;A href="http://supportcontent.checkpoint.com/file_download?id=50832" target="_blank"&gt;http://supportcontent.checkpoint.com/file_download?id=50832&lt;/A&gt; and replace $SPLUNK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/bin/opsec-tools binaries with these new ones.&lt;/P&gt;

&lt;P&gt;This solution is mentioned in the link which I shared in my comment:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/614787/splunk-check-point-lea-opsec-error-fatal-error-gli.html" target="_blank"&gt;https://answers.splunk.com/answers/614787/splunk-check-point-lea-opsec-error-fatal-error-gli.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check out below link by checkpoint:&lt;BR /&gt;
&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk130292" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk130292&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346833#M66994</guid>
      <dc:creator>ektasiwani</dc:creator>
      <dc:date>2020-09-29T20:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Configure the Splunk Add-on for Check Point OPSEC LEA</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346834#M66995</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;The OPSEC App Name does not contain specials characters. &lt;BR /&gt;
Try : splunklea.&lt;/P&gt;

&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 14:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configure-the-Splunk-Add-on-for-Check-Point-OPSEC-LEA/m-p/346834#M66995</guid>
      <dc:creator>Enedis</dc:creator>
      <dc:date>2019-07-03T14:42:01Z</dc:date>
    </item>
  </channel>
</rss>

