<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OPSEC LEA Linux App - does not connect in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81984#M16935</link>
    <description>&lt;P&gt;Yep, I bet we need to restart the checkpoint server...it's gonna be a while before that happens though. I will check back here if that does not fix the issue.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2013 17:24:52 GMT</pubDate>
    <dc:creator>coonsmatthew</dc:creator>
    <dc:date>2013-07-02T17:24:52Z</dc:date>
    <item>
      <title>OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81975#M16926</link>
      <description>&lt;P&gt;I am using Splunk 5.03 installed on Ubuntu. I installed the OPSEC LEA App for Checkpoint log analysis. I was able to establish a connection with our Checkpoint firewall, but now the connection is showing "Never Connected" under the "last connection" field. &lt;/P&gt;

&lt;P&gt;I used nc to verify that port 18184 is accessible from my workstation, and was able to initiate a 3 way handshake with the checkpoint server. &lt;/P&gt;

&lt;P&gt;I am using wireshark to analyse traffic going to port 18184 and I don't see that the Splunk App is even trying to connect to the checkpoint server. &lt;/P&gt;

&lt;P&gt;I tried restarting the splunk server, but I still don't see any connection to the checkpoint server. &lt;/P&gt;

&lt;P&gt;What am I missing? &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 14:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81975#M16926</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2013-07-02T14:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81976#M16927</link>
      <description>&lt;P&gt;Also, I was able to pull up the splunkd.log file and it shows this error many times over. &lt;/P&gt;

&lt;P&gt;07-02-2013 07:46:14.868 -0700 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity CC" ERROR: failed to create session (Argument is NULL or lacks some data)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81976#M16927</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2020-09-28T14:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81977#M16928</link>
      <description>&lt;P&gt;I'm actually getting SEQ/ACK packets between the checkpoint application and the Splunk server now. I'm not getting the "failed to create session error any more, now I'm getting this error in the splunkd.log file&lt;/P&gt;

&lt;P&gt;07-02-2013 09:00:12.632 -0700 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity Owens_cc" WARNING: Illegal entry in configuration file: SHOW_FIELDNAMES="yes"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:13:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81977#M16928</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2020-09-28T14:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81978#M16929</link>
      <description>&lt;P&gt;bug ID and workaround posted by Chubbybunny &lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/89683/warning-illegal-entry-in-configuration-file-show_fieldnamesyes-when-using-202-of-check-point-ospec-lea-application"&gt;http://splunk-base.splunk.com/answers/89683/warning-illegal-entry-in-configuration-file-show_fieldnamesyes-when-using-202-of-check-point-ospec-lea-application&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81978#M16929</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2013-07-02T16:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81979#M16930</link>
      <description>&lt;P&gt;Even though I am seeing packets being sent to checkpoint from Splunk and vice versa, the app is still showing "never connected." There does not seem to be any data being indexed as well...if I "follow TCP Stream" in wireshark, I get this output: Y......EY.......local_sic_name.....local_sic_name.....local_sic_name.........cp_local.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:13:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81979#M16930</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2020-09-28T14:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81980#M16931</link>
      <description>&lt;P&gt;would it all be possible to run the APP in debug mode?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/89743/what-is-the-easiest-way-to-debug-the-check-point-opsec-lea-app"&gt;http://splunk-base.splunk.com/answers/89743/what-is-the-easiest-way-to-debug-the-check-point-opsec-lea-app&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81980#M16931</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2013-07-02T16:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81981#M16932</link>
      <description>&lt;P&gt;I ran in debug mode, I keep on getting these errors:&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:43:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81981#M16932</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2013-07-02T16:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81982#M16933</link>
      <description>&lt;P&gt;[ 5835 3075970752]@ubuntu[2 Jul  9:30:39] opsec_auth_client_connected: connect failed (119)&lt;BR /&gt;
[ 5835 3075970752]@ubuntu[2 Jul  9:30:39] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea&lt;BR /&gt;
[ 5835 3075970752]@ubuntu[2 Jul  9:30:39] opsec_auth_client_connected:conn=(nil) opaque=0x87fe120 err=0 comm=0x87eb440&lt;BR /&gt;
[ 5835 3075970752]@ubuntu[2 Jul  9:30:39] comm failed to connect 0x87eb440&lt;BR /&gt;
[ 5835 3075970752]@ubuntu[2 Jul  9:30:39] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81982#M16933</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2020-09-28T14:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81983#M16934</link>
      <description>&lt;P&gt;'err=8' seems to indicate a problem communicating with the LEA Server for some reason per:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://forums.checkpoint.com/forums/thread.jspa?threadID=13321"&gt;https://forums.checkpoint.com/forums/thread.jspa?threadID=13321&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;use NETCAT to test the lea server on ports 18184/tcp | pullcert 18210/tcp for an open connection&lt;BR /&gt;
if any, restart the mgmt server???&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 16:59:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81983#M16934</guid>
      <dc:creator>Chubbybunny</dc:creator>
      <dc:date>2013-07-02T16:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: OPSEC LEA Linux App - does not connect</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81984#M16935</link>
      <description>&lt;P&gt;Yep, I bet we need to restart the checkpoint server...it's gonna be a while before that happens though. I will check back here if that does not fix the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2013 17:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/OPSEC-LEA-Linux-App-does-not-connect/m-p/81984#M16935</guid>
      <dc:creator>coonsmatthew</dc:creator>
      <dc:date>2013-07-02T17:24:52Z</dc:date>
    </item>
  </channel>
</rss>

