All Apps and Add-ons

Checkpoint OPSEC LEA Add-On 4.3.1 "origin_sic_name=XXXX" not in the traffic log anymore

marc_houppertz
Engager

Hi,

After upgrade of the app to 4.3.1 I notice that I don't have in trafic log the info about origin_sic_name=
For the sourcetype=opsec (for the other sourcetype, I have the info in the log)
The field I used to ID wich firewall log it belonged to in the setup of a cluster.

where is this log tag gone ? how to reactivate it ?

Marc

mvagionakis
Path Finder

the same for me. Since last update, the origin_sic_name doesn't appear anymore.
Probable there was a change in eventgen.conf since last update (?).

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...