<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point opsec lea upgrade v3.1 to v4.1 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263120#M50506</link>
    <description>&lt;P&gt;Here is the migration guide from 3.1 to 4 for reference:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ensure appropriate starttime is set for a smoother transition!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2016 17:57:31 GMT</pubDate>
    <dc:creator>mreynov_splunk</dc:creator>
    <dc:date>2016-10-21T17:57:31Z</dc:date>
    <item>
      <title>Check Point opsec lea upgrade v3.1 to v4.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263117#M50503</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm actually using the TA version 3.1 with one CMA. The TA is installed on a forwarder node.&lt;BR /&gt;
I'd like to upgrade to version4.1 but it is stated in the installation doc:&lt;BR /&gt;
&lt;EM&gt;"You cannot upgrade from a previous version of the add-on. You must remove the previous version of the add-on before installing the new version."&lt;/EM&gt;&lt;BR /&gt;
So per my understanding I cannot upgrade without stopping indexing logs during the process, correct?&lt;BR /&gt;
Perhaps I can install the new version on another forwarder, establish the SIC with the CMA and failover to this new node?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 08:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263117#M50503</guid>
      <dc:creator>sassens1</dc:creator>
      <dc:date>2016-10-18T08:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point opsec lea upgrade v3.1 to v4.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263118#M50504</link>
      <description>&lt;P&gt;Hi sassens1, &lt;/P&gt;

&lt;P&gt;Yes, you are basically right. OPSEC LEA Add-on 4.x is installed in a different folder (Splunk_TA_checkpoint-opseclea) than version 3.x, so installing 4.x is tantamount to installing a new add-on. Also, the internal data processing logic has changed in 4.X. &lt;BR /&gt;
So, you need to either uninstall or disable the older version of OPSEC LEA Add-on and install the new 4.X version. If you keep the older version running, there will be duplicate input data. &lt;/P&gt;

&lt;P&gt;Hope it helps. Thanks!&lt;BR /&gt;
Hunter&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263118#M50504</guid>
      <dc:creator>hunters_splunk</dc:creator>
      <dc:date>2020-09-29T11:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point opsec lea upgrade v3.1 to v4.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263119#M50505</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;thanks for your answer. So if I have both version running at the same time I'll have duplicate log indexing. OK so perhaps that's a better solution than just disabling/uninstalling v3 and enabling v4. It will last only the time to switch from v3 to v4 a couple of minutes I suppose.&lt;BR /&gt;
I'd like to ensure a smooth migration without loosing logs. &lt;BR /&gt;
What do you think?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 10:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263119#M50505</guid>
      <dc:creator>sassens1</dc:creator>
      <dc:date>2016-10-18T10:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point opsec lea upgrade v3.1 to v4.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263120#M50506</link>
      <description>&lt;P&gt;Here is the migration guide from 3.1 to 4 for reference:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ensure appropriate starttime is set for a smoother transition!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 17:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263120#M50506</guid>
      <dc:creator>mreynov_splunk</dc:creator>
      <dc:date>2016-10-21T17:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point opsec lea upgrade v3.1 to v4.1</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263121#M50507</link>
      <description>&lt;P&gt;Here is the migration guide from 3.1 to 4 for reference:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide"&gt;http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Ensure appropriate starttime is set for a smoother transition!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 17:58:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Check-Point-opsec-lea-upgrade-v3-1-to-v4-1/m-p/263121#M50507</guid>
      <dc:creator>mreynov_splunk</dc:creator>
      <dc:date>2016-10-21T17:58:15Z</dc:date>
    </item>
  </channel>
</rss>

