<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error regarding Checkpoint OPSEC LEA in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436981#M5789</link>
    <description>&lt;P&gt;@gjanders is right, you will need the libraries installed, configuring on the heavy forwarder is the desired method, and as for working with r70, if you can find an older version of the app, it may work.  I would personally look into upgrading my checkpoint instances to r80.10.  I just moved ours from r77.30 to r80.10 and couldn't be happier with them after working out some kinks.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Oct 2018 22:41:07 GMT</pubDate>
    <dc:creator>jchapell</dc:creator>
    <dc:date>2018-10-17T22:41:07Z</dc:date>
    <item>
      <title>Error regarding Checkpoint OPSEC LEA</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436979#M5787</link>
      <description>&lt;P&gt;I have installed the splunk Add-on on the Heavyforwarders and when trying to establishing the connection over TCP 18184 and hitting on save, its throwing up this error&lt;/P&gt;

&lt;P&gt;External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - GNU C library (glibc.i686 32-bit and pam.i686) is missing.'. See splunkd.log for stderr output.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Do i need to install the 32bit lib files as requirement ?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Is configuring add-on, on the heavyfowarders the recommended way?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The checkpoint servers in my company are very outdated currently running major version R70 but the minimum requirement in splunk is R76 ? will it still work when configured. Please help&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 17 Oct 2018 19:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436979#M5787</guid>
      <dc:creator>kartreddy4</dc:creator>
      <dc:date>2018-10-17T19:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Error regarding Checkpoint OPSEC LEA</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436980#M5788</link>
      <description>&lt;P&gt;(1) Yes, or at least in the older versions you did&lt;BR /&gt;
(2) Yes&lt;BR /&gt;
(3) No idea, you might have to test it and see but I suspect Splunk support would be "best effort" if your using an incompatible version of the firewall logging server!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 21:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436980#M5788</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2018-10-17T21:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error regarding Checkpoint OPSEC LEA</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436981#M5789</link>
      <description>&lt;P&gt;@gjanders is right, you will need the libraries installed, configuring on the heavy forwarder is the desired method, and as for working with r70, if you can find an older version of the app, it may work.  I would personally look into upgrading my checkpoint instances to r80.10.  I just moved ours from r77.30 to r80.10 and couldn't be happier with them after working out some kinks.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 22:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Error-regarding-Checkpoint-OPSEC-LEA/m-p/436981#M5789</guid>
      <dc:creator>jchapell</dc:creator>
      <dc:date>2018-10-17T22:41:07Z</dc:date>
    </item>
  </channel>
</rss>

