<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OPSEC-lea with Provider-1 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79724#M16378</link>
    <description>&lt;P&gt;has anyone been able to get the 2.0 version of SPLUNK OPSEC LEA working with this same Checkpoint architecture ?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Apr 2013 19:57:08 GMT</pubDate>
    <dc:creator>EricPartington</dc:creator>
    <dc:date>2013-04-22T19:57:08Z</dc:date>
    <item>
      <title>OPSEC-lea with Provider-1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79721#M16375</link>
      <description>&lt;P&gt;Hello everyone,
Does someone make the OPSEC-LEA app work with Provider-1?
The main difference here is that the logs are sent directly to the CLM, not to the CMA.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;

&lt;P&gt;Best Regards,
Alex&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2011 23:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79721#M16375</guid>
      <dc:creator>afaraino</dc:creator>
      <dc:date>2011-04-12T23:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC-lea with Provider-1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79722#M16376</link>
      <description>&lt;P&gt;Found the answer myself. I could help so I'm posting it there :
Here is how it works :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;SIC is established with the &lt;STRONG&gt;CMA&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;"fw putkey ..." is done on the &lt;STRONG&gt;CLM&lt;/STRONG&gt;. Furthermore, I replaced the port 18184 by "fw". &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The command became :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;opsec_putkey -ssl -port fw &amp;lt;Source IP address of CLM&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Finnally, here is my lea.conf :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;opsec_sic_name "CN=SplunkLEA,O=cma-xxxx"
opsec_sslca_file /opt/splunk/etc/apps/lea-loggrabber-splunk/bin/opsec.p12 
lea_server ip &amp;lt;Source IP address of CLM&amp;gt;
lea_server auth_port 18184
lea_server auth_type ssl_opsec
lea_server opsec_entity_sic_name "CN=clm-xxxx"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 13 Apr 2011 22:15:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79722#M16376</guid>
      <dc:creator>afaraino</dc:creator>
      <dc:date>2011-04-13T22:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC-lea with Provider-1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79723#M16377</link>
      <description>&lt;P&gt;Note that this applies to versions of the Splunk/OPSEC LEA integration prior to version 2.0.0.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2013 23:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79723#M16377</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2013-04-09T23:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC-lea with Provider-1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79724#M16378</link>
      <description>&lt;P&gt;has anyone been able to get the 2.0 version of SPLUNK OPSEC LEA working with this same Checkpoint architecture ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 19:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-lea-with-Provider-1/m-p/79724#M16378</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2013-04-22T19:57:08Z</dc:date>
    </item>
  </channel>
</rss>

