<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LEA Client doesn't connect to Check Point OPSEC LEA Server in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174831#M23328</link>
    <description>&lt;P&gt;Hope , you are using heavy forwarder installed with "Splunk add-on for checkpoint OPSEC lea" &lt;/P&gt;

&lt;P&gt;are you able to successfully create a new connection entry in the app "Splunk add-on for checkpoint OPSEC lea" ?&lt;/P&gt;

&lt;P&gt;Provide the SIC  Name &amp;amp; Entity SIC name correctly , while you add a new connection instance. On successful creation , you will see the Last Updated column getting populated with latest time&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jun 2015 04:40:46 GMT</pubDate>
    <dc:creator>splunker12er</dc:creator>
    <dc:date>2015-06-25T04:40:46Z</dc:date>
    <item>
      <title>LEA Client doesn't connect to Check Point OPSEC LEA Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174830#M23327</link>
      <description>&lt;P&gt;I am getting the errors below when i try to made a new connection to a checkpoint log server&lt;/P&gt;

&lt;P&gt;my opsec.log &lt;BR /&gt;
2015-06-25 03:25:04,408 [ERROR] [] params: {'model': u'{"opsec_host":"10.95.3.6","conn_name":"tcxf2-lon_primary","opsec_app_name":"SplunkLea","opsec_key":"$91u^k15"}'}&lt;BR /&gt;
2015-06-25 03:25:27,508 [ERROR] [] params: {'model': u'{"opsec_host":"10.95.3.6","conn_name":"tcxf2-lon_primary","opsec_app_name":"SplunkLea","opsec_key":"$91u^k15"}'}&lt;/P&gt;

&lt;P&gt;i went through the system requirement and installed the latest pam and glibc but that did not resolve my issue. not sure what am i missing&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/OPSEC-LEA/3.0.0/Install/Systemrequirements" target="_blank"&gt;http://docs.splunk.com/Documentation/OPSEC-LEA/3.0.0/Install/Systemrequirements&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;[splunk@pucu-spf-44 bin]$ /opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/pull-cert.sh&lt;BR /&gt;
unknown parameter ../certs/&lt;/P&gt;

&lt;P&gt;CheckPoint 2001. Getting an object's certificate. Works once per certificate.&lt;/P&gt;

&lt;P&gt;Usage: opsec_pull_cert -h host -n object-name -p passwd [-o cert_file] [-od dn_file]&lt;BR /&gt;
-p is the one-time-password given in the SmartDashboard when defining this entity.&lt;BR /&gt;
-o is for the output certificate file. default is "($OPSECDIR/)opsec.p12".&lt;BR /&gt;
-od is for the output sic name (one line text file).&lt;BR /&gt;
A relative path filename will be concatenated to OPSECDIR env variable (if exists).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174830#M23327</guid>
      <dc:creator>d646800</dc:creator>
      <dc:date>2020-09-28T20:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: LEA Client doesn't connect to Check Point OPSEC LEA Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174831#M23328</link>
      <description>&lt;P&gt;Hope , you are using heavy forwarder installed with "Splunk add-on for checkpoint OPSEC lea" &lt;/P&gt;

&lt;P&gt;are you able to successfully create a new connection entry in the app "Splunk add-on for checkpoint OPSEC lea" ?&lt;/P&gt;

&lt;P&gt;Provide the SIC  Name &amp;amp; Entity SIC name correctly , while you add a new connection instance. On successful creation , you will see the Last Updated column getting populated with latest time&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 04:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174831#M23328</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2015-06-25T04:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: LEA Client doesn't connect to Check Point OPSEC LEA Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174832#M23329</link>
      <description>&lt;P&gt;yes, heavy forwarder for sure&lt;/P&gt;

&lt;P&gt;this is the error when i try to create new connection- it does not even create the connection sucessfully. i use "i need to get new certificates" so i am not being asked to enter SIC Name &amp;amp; Entity SIC name&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 05:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174832#M23329</guid>
      <dc:creator>d646800</dc:creator>
      <dc:date>2015-06-25T05:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: LEA Client doesn't connect to Check Point OPSEC LEA Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174833#M23330</link>
      <description>&lt;P&gt;Did u provide the below details correctly, to pull a certificate&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Type the OPSEC App Name, for example SplunkLEA &lt;/LI&gt;
&lt;LI&gt;Type the One-time Password&lt;/LI&gt;
&lt;LI&gt;Type the Management Server IP address.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;eg:&lt;BR /&gt;
Connection name : LEA10.95.3.6&lt;BR /&gt;
Log Server IP : 10.95.3.6&lt;BR /&gt;
Log Server Port ; 18184&lt;BR /&gt;
Verion : &lt;EM&gt;choose you device version&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Once , pulled the certificate, it  is stored under the .p12 file.&lt;/P&gt;

&lt;P&gt;Note: If you receive an error message, this might be because you are attempting to pull the same certificate for the same Connection Name, using an invalid password or IP address, or the connection to the server is down. For additional error details, see $SPLUNK_HOME/var/log/splunk/web_service.log.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174833#M23330</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2020-09-28T20:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: LEA Client doesn't connect to Check Point OPSEC LEA Server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174834#M23331</link>
      <description>&lt;P&gt;had a similar issue the other week, and was able to resolve it by installing the Check Point database after creating the SplunkLEA OPSEC app. &lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 16:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/LEA-Client-doesn-t-connect-to-Check-Point-OPSEC-LEA-Server/m-p/174834#M23331</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2015-06-25T16:33:58Z</dc:date>
    </item>
  </channel>
</rss>

