<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Add-on for Check Point OPSEC LEA problem in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256217#M73787</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I've installed and configured the Splunk Add-on for Check Point OPSEC LEA.&lt;BR /&gt;
I was able to pull the certificate but it never connects to the Checkpoint Firewall. In the last conection column it says "Never Connected".&lt;BR /&gt;
I've also run a tcpdump on the splunk server and no connection is seen to the firewall. So it's not s a connectivity problem because Splunk don't even try to connect.&lt;/P&gt;

&lt;P&gt;I've run a ./splunk cmd /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh and i see some error messages such as &lt;STRONG&gt;ERROR: SIC ERROR 301 - SIC Error for lea: ckpSSL ssl lib error.&lt;/STRONG&gt; between others.&lt;/P&gt;

&lt;P&gt;Please can you help me with this issue?&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;BR /&gt;
Regards&lt;/P&gt;

&lt;P&gt;Full output:&lt;BR /&gt;
[root@tropicalia bin]# ./splunk cmd /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh&lt;BR /&gt;
Using Splunk instance: /sdm/splunk, app name Splunk_TA_opseclea_linux22&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
DEBUG: LOGGRABBER configuration file is: /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/fw1-loggrabber.conf&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function logging_init_env&lt;BR /&gt;
DEBUG: function open_screen&lt;BR /&gt;
DEBUG: Open connection to screen.&lt;BR /&gt;
DEBUG: Logfilename      : fw.log&lt;BR /&gt;
DEBUG: Record Separator : |&lt;BR /&gt;
DEBUG: Resolve Addresses: No&lt;BR /&gt;
DEBUG: Show Filenames   : No&lt;BR /&gt;
DEBUG: FW1-2000         : No&lt;BR /&gt;
DEBUG: Online-Mode      : Yes&lt;BR /&gt;
DEBUG: Audit-Log        : No&lt;BR /&gt;
DEBUG: Show Fieldnames  : Yes&lt;BR /&gt;
DEBUG: function stringlist_search&lt;BR /&gt;
DEBUG: Processing Logfile: fw.log&lt;BR /&gt;
DEBUG: function read_fw1_logfile&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/&lt;BR /&gt;
splunk output: QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/&lt;/A&gt;'&lt;BR /&gt;
HTTP Status: 200.&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;!--This is to override browser formatting; see server.conf[httpServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;
&amp;lt;feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/"&amp;gt;
  &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
  &amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf&amp;lt;/id&amp;gt;
  &amp;lt;updated&amp;gt;2016-03-21T13:14:50-03:00&amp;lt;/updated&amp;gt;
  &amp;lt;generator build="f3e41e4b37b2" version="6.3.1"/&amp;gt;
  &amp;lt;author&amp;gt;
    &amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
  &amp;lt;/author&amp;gt;
  &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/_new" rel="create"/&amp;gt;
  &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/_acl" rel="_acl"/&amp;gt;
  &amp;lt;opensearch:totalResults&amp;gt;1&amp;lt;/opensearch:totalResults&amp;gt;
  &amp;lt;opensearch:itemsPerPage&amp;gt;30&amp;lt;/opensearch:itemsPerPage&amp;gt;
  &amp;lt;opensearch:startIndex&amp;gt;0&amp;lt;/opensearch:startIndex&amp;gt;
  &amp;lt;s:messages/&amp;gt;
  &amp;lt;entry&amp;gt;
    &amp;lt;title&amp;gt;CP&amp;lt;/title&amp;gt;
    &amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP&amp;lt;/id&amp;gt;
    &amp;lt;updated&amp;gt;2016-03-21T13:14:50-03:00&amp;lt;/updated&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="alternate"/&amp;gt;
    &amp;lt;author&amp;gt;
      &amp;lt;name&amp;gt;admin&amp;lt;/name&amp;gt;
    &amp;lt;/author&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="list"/&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="edit"/&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="remove"/&amp;gt;
    &amp;lt;content type="text/xml"&amp;gt;
      &amp;lt;s:dict&amp;gt;
        &amp;lt;s:key name="disabled"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:acl"&amp;gt;
          &amp;lt;s:dict&amp;gt;
            &amp;lt;s:key name="app"&amp;gt;Splunk_TA_opseclea_linux22&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_change_perms"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_app"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_global"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_user"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="modifiable"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="owner"&amp;gt;admin&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="perms"&amp;gt;
              &amp;lt;s:dict&amp;gt;
                &amp;lt;s:key name="read"&amp;gt;
                  &amp;lt;s:list&amp;gt;
                    &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                  &amp;lt;/s:list&amp;gt;
                &amp;lt;/s:key&amp;gt;
                &amp;lt;s:key name="write"&amp;gt;
                  &amp;lt;s:list&amp;gt;
                    &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                  &amp;lt;/s:list&amp;gt;
                &amp;lt;/s:key&amp;gt;
              &amp;lt;/s:dict&amp;gt;
            &amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="removable"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="sharing"&amp;gt;app&amp;lt;/s:key&amp;gt;
          &amp;lt;/s:dict&amp;gt;
        &amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:appName"&amp;gt;Splunk_TA_opseclea_linux22&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:userName"&amp;gt;nobody&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="fw_version"&amp;gt;77&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="is_disabled"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_auth_port"&amp;gt;18184&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_auth_type"&amp;gt;sslca&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_ip"&amp;gt;10.10.10.201&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="mode"&amp;gt;fw&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="no_nagle"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="online_mode"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_entity_sic_name"&amp;gt;CN=cp_mgmt,O=pogo..4bmbx4&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_sic_name"&amp;gt;CN=Splunk-Reco,O=pogo..4bmbx4&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_sslca_file"&amp;gt;../certs/pogo.p12&amp;lt;/s:key&amp;gt;
      &amp;lt;/s:dict&amp;gt;
    &amp;lt;/content&amp;gt;
  &amp;lt;/entry&amp;gt;
&amp;lt;/feed&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;mode: fw&lt;BR /&gt;
addFilter: product=VPN-1 &amp;amp; FireWall-1&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
-v opsec_sic_name CN=Splunk-Reco,O=pogo..4bmbx4 -v opsec_sslca_file ../certs/pogo.p12 -v lea_server ip 10.10.10.201 -v lea_server auth_port 18184 -v lea_server auth_type sslca -v lea_server opsec_entity_sic_name CN=cp_mgmt,O=pogo..4bmbx4 -v lea_server no_nagle&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Env Configuration:&lt;BR /&gt;
(&lt;BR /&gt;
        :type (opsec_info)&lt;BR /&gt;
        :lea_server (no_nagle&lt;BR /&gt;
                :opsec_entity_sic_name ("CN=cp_mgmt,O=pogo..4bmbx4")&lt;BR /&gt;
                :auth_type (sslca)&lt;BR /&gt;
                :auth_port (18184)&lt;BR /&gt;
                :ip (10.10.10.201)&lt;BR /&gt;
        )&lt;BR /&gt;
        :opsec_sslca_file ("../certs/pogo.p12")&lt;BR /&gt;
        :opsec_sic_name ("CN=Splunk-Reco,O=pogo..4bmbx4")&lt;BR /&gt;
)&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_shared_local_path...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_sic_policy_file...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_mt...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_init: multithread safety is not initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: path is not initialized - will initialize&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: full file name is ops_prng&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] fwprng_opsec_read_seed: file exists but seed not initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: dev_urandom_poll returned 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_file_is_intialized: seed is initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: seed init for opsec succeeded&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_create: version 5301.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: () names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_create: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: (local_sic_name) names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: (127.0.0.1) names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: ("CN=Splunk-Reco,O=pogo..4bmbx4") names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: ca_dn = [O=pogo..4bmbx4].&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: calling PM_policy_DN_conversion ..&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] CkpRegDir: Environment variable CPDIR is not set.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] GenerateGlobalEntry: Unable to get registry path&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_init_sic_id_internal: Added sic id (ctx id = 0)&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;BR /&gt;
splunk output: QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;/A&gt;'&lt;BR /&gt;
FAILED: 'HTTP/1.1 404 Not Found'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="ERROR"&amp;gt;
 In handler 'log_status': Could not find object id=1@&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;splunkd request failed, 404:&lt;BR /&gt;
        $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;BR /&gt;
        QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;/A&gt;'&lt;BR /&gt;
FAILED: 'HTTP/1.1 404 Not Found'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="ERROR"&amp;gt;
 In handler 'log_status': Could not find object id=1@&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DEBUG: Starting  fw.log 1 at offset -1&lt;BR /&gt;
DEBUG: OPSEC LEA conf file is lea.conf&lt;BR /&gt;
DEBUG: Authentication mode has been used.&lt;BR /&gt;
DEBUG: Server-IP     : 10.10.10.201&lt;BR /&gt;
DEBUG: Server-Port     : 18184&lt;BR /&gt;
DEBUG: Authentication type: sslca&lt;BR /&gt;
DEBUG: OPSEC sic certificate file name : ../certs/pogo.p12&lt;BR /&gt;
DEBUG: Server DN (sic name) : CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
DEBUG: OPSEC LEA client DN (sic name) : CN=Splunk-Reco,O=pogo..4bmbx4&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_init_entity_sic: called for the client side&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Configuring entity lea_server&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...conn_buf_size...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...no_nagle...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...port...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding rules: apply_to: ME, peer: CN=cp_mgmt,O=pogo..4bmbx4, d_ip: NULL, dport 18184, svc: lea, method: sslca&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding INBOUND rule&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding OUTBOUND rule&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: creating comm for ent=9ff18b8  peer=9ffc8a8 passive=0 key=2 info=0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] c=0x9ff18b8 s=0x9ffc8a8 comm_type=4&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...opsec_client...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: Creating session hash (size=256)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: ADDING comm=0x9fe7e40 to ent=0x9ff18b8 with key=2&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_env_get_context_id_by_peer_sic_name: found context id=0 for peer sic name=CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_env_get_sic_handle_by_context_id: found sic handle (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_sic_connect: connecting... (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] resolver_gethostbyname: Performing gethostbyname for tropicalia&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] peers addresses are&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] 192.168.4.100&lt;BR /&gt;
DEBUG: function read_fw1_logfile_start&lt;BR /&gt;
DEBUG: OPSEC session start handler was invoked&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=1 len=0 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=402&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=402 len=27 to list=0x9fe7e5c&lt;BR /&gt;
filter 0: product=VPN-1 &amp;amp; FireWall-1&lt;BR /&gt;
DEBUG: function create_fw1_filter_rule&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_get_token&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=40f&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=40f len=139 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_conn_params:  -&amp;gt; &lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_connbuf_realloc: reallocating 0 from 0 to 1028&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_connbuf_realloc: reallocating 0 from 0 to 1028&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] sic_client_set_version: 10: protocol version is 59000000&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] call_handlers_list: no conversion done, set CN=cp_mgmt,O=pogo..4bmbx4 as sic name&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_session_init: given session O(CN=Splunk-Reco,O=pogo..4bmbx4;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: input session O(CN=Splunk-Reco,O=pogo..4bmbx4;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: rule found (ME;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea;sslca(1/1)).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: finished successfully. 1st method = sslca&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_choose: finished successfully. choose: sslca.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] do_getver: can't get inode of .//session.NDB: No such file or directory&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] sslca_read_session: failed to get cached session&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] auth_sslca_client_handler: failed to read session&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] ckpSSL_PrepareConnection: verify mode: 3&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] My SSL Ciphers:&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] Cipher List:&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 0: DES-CBC3-SHA            SSLv3 Kx=RSA      Au=RSA  Enc=3DES(168) Mac=SHA1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 1: RC4-SHA                 SSLv3 Kx=RSA      Au=RSA  Enc=RC4(128)  Mac=SHA1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 2: RC4-MD5                 SSLv3 Kx=RSA      Au=RSA  Enc=RC4(128)  Mac=MD5&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] ckpSSL_NegotiateStep: current state = before/connect initialization&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] is_initialized: new process or forked&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] fwprng_get_entropy_collection_time_opsec: value read is 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] cpprng_get_opsec_entropy_collection_time: entropy_collection time returned is 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:40] fwprng_set_entropy_collection_time_opsec: entering time is Mon Mar 21 13:15:40 2016 (1458576940)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_fwasync_connected: no connections err -3&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_fwasync_close: start shutdown&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] sic_client_end_handler: for conn id = 10&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: connect failed (301)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: SIC Error for lea: ckpSSL ssl lib error&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected:conn=(nil) opaque=0x9ffc838 err=0 comm=0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] comm failed to connect 0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] COM 0x9fe7e40 got signal 131075&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] destroying comm 0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying comm 0x9fe7e40 with 1 active sessions&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying session (a0000c8) id 3 (ent=9ff18b8) reason=SIC_FAILURE&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] SESSION ID:3 is sending DG_TYPE=3&lt;/P&gt;

&lt;P&gt;DEBUG: OPSEC_SESSION_END_HANDLER called&lt;BR /&gt;
ERROR: SIC ERROR 301 - SIC Error for lea: ckpSSL ssl lib error&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_comm_is_needed:comm 0x9fe7e40 1/1 sessions need the comm.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=1 len=0 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=402 len=27 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=40f len=139 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=ffffffff len=-1 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] REMOVING comm=0x9fe7e40 from ent=0x9ff18b8 with key=2&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_ShutdownHandler: rc=1 (0) SSLv3 read server hello A&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_ShutdownHandler: sync shutdown (fd=10)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_Destroy: closed fd 10&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] T_event_mainloop_e: T_event_mainloop_iter returns 0&lt;BR /&gt;
DEBUG: function cleanup_fw1_environment&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying entity 1 with 0 active comms&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_destroy_entity_sic: deleting sic rules for entity 0x9ff18b8&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying entity 2 with 0 active comms&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_destroy_entity_sic: deleting sic rules for entity 0x9ffc8a8&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] IpcUnMapFile: unmapping file (handle=0x9fe7768)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7848)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe78c8)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7968)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7c90)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] PM_policy_destroy: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] opsec_destroy_sic_id_internal: Destroyed sic id (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] opsec_env_destroy_sic_id_hash: Destroyed sic id hash&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] fwd_env_destroy: env 0x9fcb108 (alloced = 1)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] T_env_destroy: env 0x9fcb108&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] do_fwd_env_destroy:  really destroy 0x9fcb108&lt;BR /&gt;
DEBUG: function close_screen&lt;BR /&gt;
DEBUG: Close connection to screen.&lt;BR /&gt;
DEBUG: function exit_loggrabber&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;BR /&gt;
DEBUG: function free_afield_arrays&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;/P&gt;

&lt;H2&gt;DEBUG: function free_afield_arrays&lt;/H2&gt;

&lt;P&gt;This is the opsec.conf:&lt;BR /&gt;
[root@tropicalia ~]# cat /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/local/opsec.conf&lt;BR /&gt;
[CP]&lt;BR /&gt;
fw_version = 77&lt;BR /&gt;
is_disabled = 0&lt;BR /&gt;
lea_server_auth_port = 18184&lt;BR /&gt;
lea_server_auth_type = sslca&lt;BR /&gt;
lea_server_ip = 10.10.10.201&lt;BR /&gt;
mode = fw&lt;BR /&gt;
online_mode = 0&lt;BR /&gt;
opsec_entity_sic_name = CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
opsec_sic_name = CN=Splunk-Reco,O=pogo..4bmbx4&lt;BR /&gt;
opsec_sslca_file = ../certs/pogo.p12&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;H2&gt;no_nagle = 1&lt;/H2&gt;

&lt;P&gt;I've attached the connection configuration:&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/118171-image.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:09:17 GMT</pubDate>
    <dc:creator>noybin</dc:creator>
    <dc:date>2020-09-29T09:09:17Z</dc:date>
    <item>
      <title>Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256217#M73787</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I've installed and configured the Splunk Add-on for Check Point OPSEC LEA.&lt;BR /&gt;
I was able to pull the certificate but it never connects to the Checkpoint Firewall. In the last conection column it says "Never Connected".&lt;BR /&gt;
I've also run a tcpdump on the splunk server and no connection is seen to the firewall. So it's not s a connectivity problem because Splunk don't even try to connect.&lt;/P&gt;

&lt;P&gt;I've run a ./splunk cmd /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh and i see some error messages such as &lt;STRONG&gt;ERROR: SIC ERROR 301 - SIC Error for lea: ckpSSL ssl lib error.&lt;/STRONG&gt; between others.&lt;/P&gt;

&lt;P&gt;Please can you help me with this issue?&lt;/P&gt;

&lt;P&gt;Thank you in advance.&lt;BR /&gt;
Regards&lt;/P&gt;

&lt;P&gt;Full output:&lt;BR /&gt;
[root@tropicalia bin]# ./splunk cmd /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh&lt;BR /&gt;
Using Splunk instance: /sdm/splunk, app name Splunk_TA_opseclea_linux22&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
DEBUG: LOGGRABBER configuration file is: /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/fw1-loggrabber.conf&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_icmp&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function logging_init_env&lt;BR /&gt;
DEBUG: function open_screen&lt;BR /&gt;
DEBUG: Open connection to screen.&lt;BR /&gt;
DEBUG: Logfilename      : fw.log&lt;BR /&gt;
DEBUG: Record Separator : |&lt;BR /&gt;
DEBUG: Resolve Addresses: No&lt;BR /&gt;
DEBUG: Show Filenames   : No&lt;BR /&gt;
DEBUG: FW1-2000         : No&lt;BR /&gt;
DEBUG: Online-Mode      : Yes&lt;BR /&gt;
DEBUG: Audit-Log        : No&lt;BR /&gt;
DEBUG: Show Fieldnames  : Yes&lt;BR /&gt;
DEBUG: function stringlist_search&lt;BR /&gt;
DEBUG: Processing Logfile: fw.log&lt;BR /&gt;
DEBUG: function read_fw1_logfile&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/&lt;BR /&gt;
splunk output: QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/&lt;/A&gt;'&lt;BR /&gt;
HTTP Status: 200.&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;!--This is to override browser formatting; see server.conf[httpServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&amp;gt;
&amp;lt;?xml-stylesheet type="text/xml" href="/static/atom.xsl"?&amp;gt;
&amp;lt;feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/"&amp;gt;
  &amp;lt;title&amp;gt;&amp;lt;/title&amp;gt;
  &amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf&amp;lt;/id&amp;gt;
  &amp;lt;updated&amp;gt;2016-03-21T13:14:50-03:00&amp;lt;/updated&amp;gt;
  &amp;lt;generator build="f3e41e4b37b2" version="6.3.1"/&amp;gt;
  &amp;lt;author&amp;gt;
    &amp;lt;name&amp;gt;Splunk&amp;lt;/name&amp;gt;
  &amp;lt;/author&amp;gt;
  &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/_new" rel="create"/&amp;gt;
  &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/_acl" rel="_acl"/&amp;gt;
  &amp;lt;opensearch:totalResults&amp;gt;1&amp;lt;/opensearch:totalResults&amp;gt;
  &amp;lt;opensearch:itemsPerPage&amp;gt;30&amp;lt;/opensearch:itemsPerPage&amp;gt;
  &amp;lt;opensearch:startIndex&amp;gt;0&amp;lt;/opensearch:startIndex&amp;gt;
  &amp;lt;s:messages/&amp;gt;
  &amp;lt;entry&amp;gt;
    &amp;lt;title&amp;gt;CP&amp;lt;/title&amp;gt;
    &amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP&amp;lt;/id&amp;gt;
    &amp;lt;updated&amp;gt;2016-03-21T13:14:50-03:00&amp;lt;/updated&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="alternate"/&amp;gt;
    &amp;lt;author&amp;gt;
      &amp;lt;name&amp;gt;admin&amp;lt;/name&amp;gt;
    &amp;lt;/author&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="list"/&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="edit"/&amp;gt;
    &amp;lt;link href="/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/opsec_conf/CP" rel="remove"/&amp;gt;
    &amp;lt;content type="text/xml"&amp;gt;
      &amp;lt;s:dict&amp;gt;
        &amp;lt;s:key name="disabled"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:acl"&amp;gt;
          &amp;lt;s:dict&amp;gt;
            &amp;lt;s:key name="app"&amp;gt;Splunk_TA_opseclea_linux22&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_change_perms"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_app"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_global"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_share_user"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="modifiable"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="owner"&amp;gt;admin&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="perms"&amp;gt;
              &amp;lt;s:dict&amp;gt;
                &amp;lt;s:key name="read"&amp;gt;
                  &amp;lt;s:list&amp;gt;
                    &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                  &amp;lt;/s:list&amp;gt;
                &amp;lt;/s:key&amp;gt;
                &amp;lt;s:key name="write"&amp;gt;
                  &amp;lt;s:list&amp;gt;
                    &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                  &amp;lt;/s:list&amp;gt;
                &amp;lt;/s:key&amp;gt;
              &amp;lt;/s:dict&amp;gt;
            &amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="removable"&amp;gt;1&amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="sharing"&amp;gt;app&amp;lt;/s:key&amp;gt;
          &amp;lt;/s:dict&amp;gt;
        &amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:appName"&amp;gt;Splunk_TA_opseclea_linux22&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="eai:userName"&amp;gt;nobody&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="fw_version"&amp;gt;77&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="is_disabled"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_auth_port"&amp;gt;18184&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_auth_type"&amp;gt;sslca&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="lea_server_ip"&amp;gt;10.10.10.201&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="mode"&amp;gt;fw&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="no_nagle"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="online_mode"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_entity_sic_name"&amp;gt;CN=cp_mgmt,O=pogo..4bmbx4&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_sic_name"&amp;gt;CN=Splunk-Reco,O=pogo..4bmbx4&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="opsec_sslca_file"&amp;gt;../certs/pogo.p12&amp;lt;/s:key&amp;gt;
      &amp;lt;/s:dict&amp;gt;
    &amp;lt;/content&amp;gt;
  &amp;lt;/entry&amp;gt;
&amp;lt;/feed&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;mode: fw&lt;BR /&gt;
addFilter: product=VPN-1 &amp;amp; FireWall-1&lt;BR /&gt;
DEBUG: function string_duplicate&lt;BR /&gt;
-v opsec_sic_name CN=Splunk-Reco,O=pogo..4bmbx4 -v opsec_sslca_file ../certs/pogo.p12 -v lea_server ip 10.10.10.201 -v lea_server auth_port 18184 -v lea_server auth_type sslca -v lea_server opsec_entity_sic_name CN=cp_mgmt,O=pogo..4bmbx4 -v lea_server no_nagle&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Env Configuration:&lt;BR /&gt;
(&lt;BR /&gt;
        :type (opsec_info)&lt;BR /&gt;
        :lea_server (no_nagle&lt;BR /&gt;
                :opsec_entity_sic_name ("CN=cp_mgmt,O=pogo..4bmbx4")&lt;BR /&gt;
                :auth_type (sslca)&lt;BR /&gt;
                :auth_port (18184)&lt;BR /&gt;
                :ip (10.10.10.201)&lt;BR /&gt;
        )&lt;BR /&gt;
        :opsec_sslca_file ("../certs/pogo.p12")&lt;BR /&gt;
        :opsec_sic_name ("CN=Splunk-Reco,O=pogo..4bmbx4")&lt;BR /&gt;
)&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_shared_local_path...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_sic_policy_file...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] Could not find info for ...opsec_mt...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_init: multithread safety is not initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: path is not initialized - will initialize&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: full file name is ops_prng&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] fwprng_opsec_read_seed: file exists but seed not initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: dev_urandom_poll returned 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_file_is_intialized: seed is initialized&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] cpprng_opsec_initialize: seed init for opsec succeeded&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_create: version 5301.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: () names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_create: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: (local_sic_name) names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: (127.0.0.1) names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_add_name_to_group: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_policy_set_local_names: ("CN=Splunk-Reco,O=pogo..4bmbx4") names. finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: ca_dn = [O=pogo..4bmbx4].&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: calling PM_policy_DN_conversion ..&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] PM_apply_default_dn: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] CkpRegDir: Environment variable CPDIR is not set.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] GenerateGlobalEntry: Unable to get registry path&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 12&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 32&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 11&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] sslcaInitCP_Ex: using asym client without ca cert&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] ckpSSLctx_New: prefs = 31&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:50] opsec_init_sic_id_internal: Added sic id (ctx id = 0)&lt;BR /&gt;
splunk internal call command: $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;BR /&gt;
splunk output: QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;/A&gt;'&lt;BR /&gt;
FAILED: 'HTTP/1.1 404 Not Found'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="ERROR"&amp;gt;
 In handler 'log_status': Could not find object id=1@&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;splunkd request failed, 404:&lt;BR /&gt;
        $SPLUNK_HOME/bin/splunk _internal call /servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;BR /&gt;
        QUERYING: '&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_opseclea_linux22/opsec/log_status/1@&lt;/A&gt;'&lt;BR /&gt;
FAILED: 'HTTP/1.1 404 Not Found'&lt;BR /&gt;
Content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;response&amp;gt;
  &amp;lt;messages&amp;gt;
    &amp;lt;msg type="ERROR"&amp;gt;
 In handler 'log_status': Could not find object id=1@&amp;lt;/msg&amp;gt;
  &amp;lt;/messages&amp;gt;
&amp;lt;/response&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;DEBUG: Starting  fw.log 1 at offset -1&lt;BR /&gt;
DEBUG: OPSEC LEA conf file is lea.conf&lt;BR /&gt;
DEBUG: Authentication mode has been used.&lt;BR /&gt;
DEBUG: Server-IP     : 10.10.10.201&lt;BR /&gt;
DEBUG: Server-Port     : 18184&lt;BR /&gt;
DEBUG: Authentication type: sslca&lt;BR /&gt;
DEBUG: OPSEC sic certificate file name : ../certs/pogo.p12&lt;BR /&gt;
DEBUG: Server DN (sic name) : CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
DEBUG: OPSEC LEA client DN (sic name) : CN=Splunk-Reco,O=pogo..4bmbx4&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_init_entity_sic: called for the client side&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Configuring entity lea_server&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...conn_buf_size...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...no_nagle...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...port...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding rules: apply_to: ME, peer: CN=cp_mgmt,O=pogo..4bmbx4, d_ip: NULL, dport 18184, svc: lea, method: sslca&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding INBOUND rule&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_entity_add_sic_rule: adding OUTBOUND rule&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: creating comm for ent=9ff18b8  peer=9ffc8a8 passive=0 key=2 info=0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] c=0x9ff18b8 s=0x9ffc8a8 comm_type=4&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] Could not find info for ...opsec_client...&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: Creating session hash (size=256)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_get_comm: ADDING comm=0x9fe7e40 to ent=0x9ff18b8 with key=2&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_env_get_context_id_by_peer_sic_name: found context id=0 for peer sic name=CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_env_get_sic_handle_by_context_id: found sic handle (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] opsec_sic_connect: connecting... (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] resolver_gethostbyname: Performing gethostbyname for tropicalia&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] peers addresses are&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] 192.168.4.100&lt;BR /&gt;
DEBUG: function read_fw1_logfile_start&lt;BR /&gt;
DEBUG: OPSEC session start handler was invoked&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=1 len=0 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=402&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=402 len=27 to list=0x9fe7e5c&lt;BR /&gt;
filter 0: product=VPN-1 &amp;amp; FireWall-1&lt;BR /&gt;
DEBUG: function create_fw1_filter_rule&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
DEBUG: function string_get_token&lt;BR /&gt;
DEBUG: function string_trim&lt;BR /&gt;
DEBUG: function string_left_trim&lt;BR /&gt;
DEBUG: function string_right_trim&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] SESSION ID:3 is sending DG_TYPE=40f&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] pushing dgtype=40f len=139 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_conn_params:  -&amp;gt; &lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_connbuf_realloc: reallocating 0 from 0 to 1028&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:52] fwasync_connbuf_realloc: reallocating 0 from 0 to 1028&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] sic_client_set_version: 10: protocol version is 59000000&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] call_handlers_list: no conversion done, set CN=cp_mgmt,O=pogo..4bmbx4 as sic name&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_session_init: given session O(CN=Splunk-Reco,O=pogo..4bmbx4;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: input session O(CN=Splunk-Reco,O=pogo..4bmbx4;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: rule found (ME;CN=cp_mgmt,O=pogo..4bmbx4;18184;lea;sslca(1/1)).&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_query: finished successfully. 1st method = sslca&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] PM_policy_choose: finished successfully. choose: sslca.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:14:53] do_getver: can't get inode of .//session.NDB: No such file or directory&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] sslca_read_session: failed to get cached session&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] auth_sslca_client_handler: failed to read session&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] ckpSSL_PrepareConnection: verify mode: 3&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] My SSL Ciphers:&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] Cipher List:&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 0: DES-CBC3-SHA            SSLv3 Kx=RSA      Au=RSA  Enc=3DES(168) Mac=SHA1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 1: RC4-SHA                 SSLv3 Kx=RSA      Au=RSA  Enc=RC4(128)  Mac=SHA1&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] 2: RC4-MD5                 SSLv3 Kx=RSA      Au=RSA  Enc=RC4(128)  Mac=MD5&lt;/P&gt;

&lt;P&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] ckpSSL_NegotiateStep: current state = before/connect initialization&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] is_initialized: new process or forked&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] fwprng_get_entropy_collection_time_opsec: value read is 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:24] cpprng_get_opsec_entropy_collection_time: entropy_collection time returned is 0&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:40] fwprng_set_entropy_collection_time_opsec: entering time is Mon Mar 21 13:15:40 2016 (1458576940)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_fwasync_connected: no connections err -3&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_fwasync_close: start shutdown&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] sic_client_end_handler: for conn id = 10&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: connect failed (301)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: SIC Error for lea: ckpSSL ssl lib error&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected:conn=(nil) opaque=0x9ffc838 err=0 comm=0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] comm failed to connect 0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] COM 0x9fe7e40 got signal 131075&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] destroying comm 0x9fe7e40&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying comm 0x9fe7e40 with 1 active sessions&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying session (a0000c8) id 3 (ent=9ff18b8) reason=SIC_FAILURE&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] SESSION ID:3 is sending DG_TYPE=3&lt;/P&gt;

&lt;P&gt;DEBUG: OPSEC_SESSION_END_HANDLER called&lt;BR /&gt;
ERROR: SIC ERROR 301 - SIC Error for lea: ckpSSL ssl lib error&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_comm_is_needed:comm 0x9fe7e40 1/1 sessions need the comm.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=1 len=0 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=402 len=27 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=40f len=139 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] pulling dgtype=ffffffff len=-1 to list=0x9fe7e5c&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] REMOVING comm=0x9fe7e40 from ent=0x9ff18b8 with key=2&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_ShutdownHandler: rc=1 (0) SSLv3 read server hello A&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_ShutdownHandler: sync shutdown (fd=10)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] ckpSSL_Destroy: closed fd 10&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] T_event_mainloop_e: T_event_mainloop_iter returns 0&lt;BR /&gt;
DEBUG: function cleanup_fw1_environment&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying entity 1 with 0 active comms&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_destroy_entity_sic: deleting sic rules for entity 0x9ff18b8&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] Destroying entity 2 with 0 active comms&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_destroy_entity_sic: deleting sic rules for entity 0x9ffc8a8&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] IpcUnMapFile: unmapping file (handle=0x9fe7768)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7848)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe78c8)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7968)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] IpcUnMapFile: unmapping file (handle=0x9fe7c90)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] PM_policy_destroy: finished successfully.&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] opsec_destroy_sic_id_internal: Destroyed sic id (ctx id=0)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] opsec_env_destroy_sic_id_hash: Destroyed sic id hash&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] fwd_env_destroy: env 0x9fcb108 (alloced = 1)&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] T_env_destroy: env 0x9fcb108&lt;BR /&gt;
[ 9348 4149401280]@tropicalia[21 Mar 13:15:53] do_fwd_env_destroy:  really destroy 0x9fcb108&lt;BR /&gt;
DEBUG: function close_screen&lt;BR /&gt;
DEBUG: Close connection to screen.&lt;BR /&gt;
DEBUG: function exit_loggrabber&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;BR /&gt;
DEBUG: function free_afield_arrays&lt;BR /&gt;
DEBUG: function free_lfield_arrays&lt;/P&gt;

&lt;H2&gt;DEBUG: function free_afield_arrays&lt;/H2&gt;

&lt;P&gt;This is the opsec.conf:&lt;BR /&gt;
[root@tropicalia ~]# cat /sdm/splunk/etc/apps/Splunk_TA_opseclea_linux22/local/opsec.conf&lt;BR /&gt;
[CP]&lt;BR /&gt;
fw_version = 77&lt;BR /&gt;
is_disabled = 0&lt;BR /&gt;
lea_server_auth_port = 18184&lt;BR /&gt;
lea_server_auth_type = sslca&lt;BR /&gt;
lea_server_ip = 10.10.10.201&lt;BR /&gt;
mode = fw&lt;BR /&gt;
online_mode = 0&lt;BR /&gt;
opsec_entity_sic_name = CN=cp_mgmt,O=pogo..4bmbx4&lt;BR /&gt;
opsec_sic_name = CN=Splunk-Reco,O=pogo..4bmbx4&lt;BR /&gt;
opsec_sslca_file = ../certs/pogo.p12&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;H2&gt;no_nagle = 1&lt;/H2&gt;

&lt;P&gt;I've attached the connection configuration:&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/118171-image.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256217#M73787</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2020-09-29T09:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256218#M73788</link>
      <description>&lt;P&gt;Based on your logs it is trying to connect to the Opsec server but the connection gets refused. If you're able to pull the cert then my current best guess is that the Entity SIC Name is wrong -- some CP Admins make the FWs have custom names.  For example, they might've named it TropicalLA or something also this is case sensitive keep in mind.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256218#M73788</guid>
      <dc:creator>ryandg</dc:creator>
      <dc:date>2016-04-14T17:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256219#M73789</link>
      <description>&lt;P&gt;Hi ryandg,&lt;/P&gt;

&lt;P&gt;I don't think that it is a connectivity problem because when I run a tcpdump on the splunk server, I don't see any attempt to connect to the firewall. So splunk is not trying to reach the firewall at all.&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:40:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256219#M73789</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2016-04-14T17:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256220#M73790</link>
      <description>&lt;P&gt;If you restart splunkd while running a tcp dump, you see zero packets reaching out to the server? It just seems strange because according to your logs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: connect failed (301)
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected: SIC Error for lea: ckpSSL ssl lib error
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] opsec_auth_client_connected:conn=(nil) opaque=0x9ffc838 err=0 comm=0x9fe7e40
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] comm failed to connect 0x9fe7e40
[ 9348 4149401280]@tropicalia[21 Mar 13:15:48] OPSEC_SET_ERRNO: err = 8 Comm is not connected/Unable to connect (pre = 0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It thinks it is connecting out and attempting to reach them. Can you try starting a tcpdump on one session, double check the port and dump query and then in a second session run a splunkd restart?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256220#M73790</guid>
      <dc:creator>ryandg</dc:creator>
      <dc:date>2016-04-14T17:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256221#M73791</link>
      <description>&lt;P&gt;I've just done that and nothing is seen on the tcpdump output.&lt;/P&gt;

&lt;P&gt;tcpdump -vi ens32 host 10.10.10.201&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256221#M73791</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2016-04-14T17:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256222#M73792</link>
      <description>&lt;P&gt;Do you have any other CMAs/CLMs?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 17:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256222#M73792</guid>
      <dc:creator>ryandg</dc:creator>
      <dc:date>2016-04-14T17:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256223#M73793</link>
      <description>&lt;P&gt;I am asking to the FW admin. I will write as soon as he answers me.&lt;/P&gt;

&lt;P&gt;I also want to add that we are running Splunk on a Centos 7 and we followed the procedure below when installing the app:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/89697/check-point-ospec-lea-app-bad-elf-interpreter-error.html"&gt;https://answers.splunk.com/answers/89697/check-point-ospec-lea-app-bad-elf-interpreter-error.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 18:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256223#M73793</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2016-04-14T18:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256224#M73794</link>
      <description>&lt;P&gt;I've ran the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And that returned a lot of data. So I think that it is not a connectivity problem. The following is a little part of the output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;loc=391468|time=14Apr2016 15:57:43|action=accept|orig=salsa|i/f_dir=inbound|i/f_name=eth3.101|has_accounting=0|product=VPN-1 &amp;amp; FireWall-1|inzone=Internal|outzone=External|rule=9|rule_uid={1B559F21-9B45-4568-AB00-632D730B4B95}|session_id:=3191|dns_query=wildcard.adroll.com.edgekey.net |dns_type=A|service_id=domain-udp|src=guajira|s_port=36636|dst=208.67.220.220|service=domain-udp|proto=udp|xlatesrc=IP_Telmex_201|xlatesport=Unknown|xlatedport=Unknown|NAT_rulenum=29|NAT_addtnl_rulenum=1|__policy_id_tag=product=VPN-1 &amp;amp; FireWall-1[db_tag={C40D4BFA-4622-7247-ABD7-9B14BC334ED2};mgmt=pogo;date=1460468083;policy_name=R77-AR]|origin_sic_name=CN=salsa,O=pogo..4bmbx4
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_InputPending 1 pending bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_InputPending 1 pending bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_InputPending 1 pending bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_do_read: read 12 bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_InputPending 1 pending bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_InputPending 1 pending bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] ckpSSL_do_read: read 455 bytes
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] demultiplex type=505 session-id=3
[ 21653 4149450432]@tropicalia[14 Apr 15:57:45] client: got RECORD session 3
DEBUG: function read_fw1_logfile_record
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function string_escape
DEBUG: function string_escape
DEBUG: function string_cat
DEBUG: function submit_screen
DEBUG: Submit message to screen.
loc=391469|time=14Apr2016 15:57:43|action=drop|orig=salsa|i/f_dir=inbound|i/f_name=eth2.106|has_accounting=0|product=VPN-1 &amp;amp; FireWall-1|rule=243|rule_uid={460EDE04-17FF-49CA-A722-360A0D25294D}|src=Video-SRV|s_port=nbdatagram|dst=192.168.6.255|service=nbdatagram|proto=udp|__policy_id_tag=product=VPN-1 &amp;amp; FireWall-1[db_tag={C40D4BFA-4622-7247-ABD7-9B14BC334ED2};mgmt=pogo;date=1460468083;policy_name=R77-AR]|origin_sic_name=CN=salsa,O=pogo..4bmbx4
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Apr 2016 19:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256224#M73794</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2016-04-14T19:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256225#M73795</link>
      <description>&lt;P&gt;Could iptables (or other host-based firewall) or apparmor or SE policies be preventing the splunk service (and specifically the lea_log_grabber.sh that runs under it) be blocking outbound connections?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256225#M73795</guid>
      <dc:creator>jpvlsmv</dc:creator>
      <dc:date>2020-09-29T09:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Check Point OPSEC LEA problem</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256226#M73796</link>
      <description>&lt;P&gt;I solved the problem.&lt;/P&gt;

&lt;P&gt;Solution: &lt;BR /&gt;
1.Set the environment variable $SPLUNK_HOME&lt;BR /&gt;
2. Create a new connection&lt;BR /&gt;
3. Pull the certificate again.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 21:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Check-Point-OPSEC-LEA-problem/m-p/256226#M73796</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2016-04-14T21:13:12Z</dc:date>
    </item>
  </channel>
</rss>

