All Apps and Add-ons

Checkpoint OPSEC LEA Add-On 4.3.1 "origin_sic_name=XXXX" not in the traffic log anymore

marc_houppertz
Engager

Hi,

After upgrade of the app to 4.3.1 I notice that I don't have in trafic log the info about origin_sic_name=
For the sourcetype=opsec (for the other sourcetype, I have the info in the log)
The field I used to ID wich firewall log it belonged to in the setup of a cluster.

where is this log tag gone ? how to reactivate it ?

Marc

mvagionakis
Path Finder

the same for me. Since last update, the origin_sic_name doesn't appear anymore.
Probable there was a change in eventgen.conf since last update (?).

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...