<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: troubleshooting splunk-checkpoint communication in Installation</title>
    <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15630#M9117</link>
    <description>&lt;P&gt;jonathanhowell -&lt;/P&gt;

&lt;P&gt;Splunk's lea_loggrabber app is open-source. I have a patch which enables more verbose logging - quite useful for debugging lea_loggrabber issues. (It also includes a few other enhancements.) It's working very well for months now, not only in my environment but elsewhere. I've requested Splunk to either grant me commit access to their google code project for lea_loggrabber or at least to review my patch and make it available. Unfortunately no action on their side to date, other than opening the source. Send me a direct message with your email address and I'll send you a package with the patch, readme, plus some support scripts and useful lookups.&lt;/P&gt;

&lt;P&gt;Cheers, --Trey&lt;/P&gt;</description>
    <pubDate>Tue, 07 Sep 2010 20:14:27 GMT</pubDate>
    <dc:creator>treyka</dc:creator>
    <dc:date>2010-09-07T20:14:27Z</dc:date>
    <item>
      <title>troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15628#M9115</link>
      <description>&lt;P&gt;I am evaluating Splun 4.x as my log file analyzer for a Checkpoint UTM-1. I followed the procedures for configuring an LEA connector &amp;amp; setting up OPSEC. It appears that Splunk is running &amp;amp; making LEA requests of the Checkpoint, but I get no data logged on Splunk.&lt;/P&gt;

&lt;P&gt;How can I best go about troubleshooting this? What log files or debug commands can i use to trace down the fault?&lt;/P&gt;

&lt;P&gt;I appreciate your help.
Jonathan&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2010 00:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15628#M9115</guid>
      <dc:creator>jonathanhowell</dc:creator>
      <dc:date>2010-06-17T00:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15629#M9116</link>
      <description>&lt;P&gt;The splunkd.log at $SPLUNK_HOME/var/log/splunk/ is usually good for this sort of troubleshooting.  If for some reason an input is being skipped, this will often be the place that it's logged.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2010 02:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15629#M9116</guid>
      <dc:creator>Yancy</dc:creator>
      <dc:date>2010-06-17T02:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15630#M9117</link>
      <description>&lt;P&gt;jonathanhowell -&lt;/P&gt;

&lt;P&gt;Splunk's lea_loggrabber app is open-source. I have a patch which enables more verbose logging - quite useful for debugging lea_loggrabber issues. (It also includes a few other enhancements.) It's working very well for months now, not only in my environment but elsewhere. I've requested Splunk to either grant me commit access to their google code project for lea_loggrabber or at least to review my patch and make it available. Unfortunately no action on their side to date, other than opening the source. Send me a direct message with your email address and I'll send you a package with the patch, readme, plus some support scripts and useful lookups.&lt;/P&gt;

&lt;P&gt;Cheers, --Trey&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2010 20:14:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15630#M9117</guid>
      <dc:creator>treyka</dc:creator>
      <dc:date>2010-09-07T20:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15631#M9118</link>
      <description>&lt;P&gt;Trey&lt;/P&gt;

&lt;P&gt;We are experiencing the exact same behaviour than ‘Starlette’ in
&lt;A rel="nofollow" href="http://answers.splunk.com/questions/947/splunking-my-checkpoint-firewall-logs"&gt;http://answers.splunk.com/questions/947/splunking-my-checkpoint-firewall-logs&lt;/A&gt;
We are interested to your package with the patch.
We are running on RedHat 5-64.
How can we get it?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Cheers, JP&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2010 01:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15631#M9118</guid>
      <dc:creator>jplaberge</dc:creator>
      <dc:date>2010-09-09T01:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15632#M9119</link>
      <description>&lt;P&gt;Hello Trey,&lt;BR /&gt;
Thank you for taking the time to enhance this app and share that with other users.&lt;BR /&gt;
I'll send you my email address to get a copy of your package. I will give it a go and try to give some traction to your request if it proves helpful in troubleshooting jplaberge's issue.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2010 01:43:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15632#M9119</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2010-09-09T01:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting splunk-checkpoint communication</title>
      <link>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15633#M9120</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We are also interested in your package...
possible to take a look?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Cheers,
Vincent&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2011 09:47:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/troubleshooting-splunk-checkpoint-communication/m-p/15633#M9120</guid>
      <dc:creator>csoh</dc:creator>
      <dc:date>2011-04-05T09:47:19Z</dc:date>
    </item>
  </channel>
</rss>

