All Apps and Add-ons

Checkpoint OPSEC LEA Error

robertgoolsby
Engager
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: rule not found.
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: finished successfully. 1st method = deny
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_choose: finished successfully. choose: DENY.
[ 32278 4158076608]@host[5 Dec 11:08:42] policy_choose: choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_negotiate_auth_method: policy choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] fwasync_mux_in: 10: handler returned with error
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_end_handler: for conn id = 10
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: connect failed (119)
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected:conn=(nil) opaque=0x8595218 err=0 comm=0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] comm failed to connect 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] OPSEC_SET_ERRNO: err =  8  Comm is not connected/Unable to connect (pre =  0)
[ 32278 4158076608]@host[5 Dec 11:08:42] COM 0x858be20 got signal 131075
[ 32278 4158076608]@host[5 Dec 11:08:42] destroying comm 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying comm 0x858be20 with 1 active sessions
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying session (85a34f0) id 3 (ent=8595a18) reason=SIC_FAILURE
[ 32278 4158076608]@host[5 Dec 11:08:42] SESSION ID:3 is sending DG_TYPE=3

DEBUG: function get_fw1_logfiles_end
DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

We see Splunk and checkpoint talking but no logs are being added to the index.

0 Karma

rroussev_splunk
Splunk Employee
Splunk Employee

Please verify that the lea port is correct and check http://docs.splunk.com/Documentation/OPSEC-LEA/latest/Install/SetupSSLCAauthentication. If you're still having problems, please file a support ticket.

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...