<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OPSEC LEA - *** Confidential *** in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55540#M70325</link>
    <description>&lt;P&gt;To fix such issues please follow the steps below.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Open Smart Dashboard. Go to OPEC Splunk object. Then click on LEA Permissions.&lt;BR /&gt;
Here you need to Change "Permission to read logs" to Show all log fields. By default this is set to "Hide all confidential log fields".&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Install Database and then Push policy&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;reboot Check Point management server.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I tried cpstop/cpstart on management server and also re-setting LEA connection from OPSEC LEA's state settings (disable/enable) but I could still see many fileds as confidential in Check Point logs. After reboot of Check Point Management server this issue was resolved.&lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
Ashok&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25i1C9DF67D2A304150/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2015 05:55:38 GMT</pubDate>
    <dc:creator>ashokqos</dc:creator>
    <dc:date>2015-09-03T05:55:38Z</dc:date>
    <item>
      <title>OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55536#M70321</link>
      <description>&lt;P&gt;I have just gotten a Splunk instance running and am working on including logs from our Check Point Smart-1 management server. I've followed the docs for the Splunk OPSEC LEA add on without any significant problems and am receiving data from the management server.&lt;/P&gt;

&lt;P&gt;However, many of the fields are coming across as "*** Confidential ***". Is there any way to get the real values?&lt;/P&gt;

&lt;P&gt;Fields affected include (but not limited to): &lt;CODE&gt;user, src_user_name, src_machine_name, dst_user_name, dst_machine_name, appi_name, app_desc, app_risk, app_rule_id&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Here's a sample record:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;loc=33292 filename=fw.log fileid=1337354883 time=18May2012 12:31:28 action=reject orig=UTM1 i/f_dir=inbound i/f_name=Internal has_accounting=0 product=VPN-1 &amp;amp; FireWall-1 __policy_id_tag=product=VPN-1 &amp;amp; FireWall-1[db_tag={9E77F78D-A0EE-12E1-97FE-000000001819};mgmt=fwmgmt;date=1337355553;policy_name=Standard] user=*** Confidential *** src_user_name=*** Confidential *** src_machine_name=*** Confidential *** dst_user_name=*** Confidential *** dst_machine_name=*** Confidential *** snid=7f006812 rule=74 rule_uid={3CEEDB7D-72AE-469C-862B-A329CE4F2E2C} src=userpc1 s_port=17500 dst=255.255.255.255 service=17500 proto=udp
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 May 2012 17:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55536#M70321</guid>
      <dc:creator>PunchMonkey</dc:creator>
      <dc:date>2012-05-18T17:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55537#M70322</link>
      <description>&lt;P&gt;After speaking with our Check Point support team, it seems this is an issue introduced in R75.20 as a "feature". To get the expected behaviour, you need to apply a hot fix to the management server.&lt;/P&gt;

&lt;P&gt;I've applied the fix in our environment and it's working well.&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2012 21:42:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55537#M70322</guid>
      <dc:creator>PunchMonkey</dc:creator>
      <dc:date>2012-05-22T21:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55538#M70323</link>
      <description>&lt;P&gt;just curious ... which hot fix id or version did you happen to apply to the mgmt server?&lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2012 21:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55538#M70323</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2012-05-22T21:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55539#M70324</link>
      <description>&lt;P&gt;Looks like now in R77 there is no need for the hot fix but if you see "Confidential" in the logs it is because the OPSEC application object in SmartDashboard is not set to the "Show all log fields" option in the "LEA Permissions" tab. See &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101570&amp;amp;js_peid=P-14d3e6d9e20-10001&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk101570&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 16:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55539#M70324</guid>
      <dc:creator>worshamn</dc:creator>
      <dc:date>2015-05-26T16:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55540#M70325</link>
      <description>&lt;P&gt;To fix such issues please follow the steps below.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Open Smart Dashboard. Go to OPEC Splunk object. Then click on LEA Permissions.&lt;BR /&gt;
Here you need to Change "Permission to read logs" to Show all log fields. By default this is set to "Hide all confidential log fields".&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Install Database and then Push policy&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;reboot Check Point management server.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I tried cpstop/cpstart on management server and also re-setting LEA connection from OPSEC LEA's state settings (disable/enable) but I could still see many fileds as confidential in Check Point logs. After reboot of Check Point Management server this issue was resolved.&lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
Ashok&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25i1C9DF67D2A304150/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 05:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55540#M70325</guid>
      <dc:creator>ashokqos</dc:creator>
      <dc:date>2015-09-03T05:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55541#M70326</link>
      <description>&lt;P&gt;If the issue still persists please refer Checkpoint's sk103758 and sk101570&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 09:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55541#M70326</guid>
      <dc:creator>ashokqos</dc:creator>
      <dc:date>2015-09-04T09:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA - *** Confidential ***</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55542#M70327</link>
      <description>&lt;P&gt;Upvoted. Rebooting the Check Point managent server helped.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 10:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OPSEC-LEA-Confidential/m-p/55542#M70327</guid>
      <dc:creator>Yunagi</dc:creator>
      <dc:date>2018-05-24T10:57:04Z</dc:date>
    </item>
  </channel>
</rss>

