[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: rule not found.
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_query: finished successfully. 1st method = deny
[ 32278 4158076608]@host[5 Dec 11:08:42] PM_policy_choose: finished successfully. choose: DENY.
[ 32278 4158076608]@host[5 Dec 11:08:42] policy_choose: choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_negotiate_auth_method: policy choose failed.
[ 32278 4158076608]@host[5 Dec 11:08:42] fwasync_mux_in: 10: handler returned with error
[ 32278 4158076608]@host[5 Dec 11:08:42] sic_client_end_handler: for conn id = 10
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: connect failed (119)
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected: SIC Error for lea: Client could not choose an authentication method for service lea
[ 32278 4158076608]@host[5 Dec 11:08:42] opsec_auth_client_connected:conn=(nil) opaque=0x8595218 err=0 comm=0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] comm failed to connect 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] OPSEC_SET_ERRNO: err = 8 Comm is not connected/Unable to connect (pre = 0)
[ 32278 4158076608]@host[5 Dec 11:08:42] COM 0x858be20 got signal 131075
[ 32278 4158076608]@host[5 Dec 11:08:42] destroying comm 0x858be20
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying comm 0x858be20 with 1 active sessions
[ 32278 4158076608]@host[5 Dec 11:08:42] Destroying session (85a34f0) id 3 (ent=8595a18) reason=SIC_FAILURE
[ 32278 4158076608]@host[5 Dec 11:08:42] SESSION ID:3 is sending DG_TYPE=3
DEBUG: function get_fw1_logfiles_end
DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea
We see Splunk and checkpoint talking but no logs are being added to the index.
Please verify that the lea port is correct and check http://docs.splunk.com/Documentation/OPSEC-LEA/latest/Install/SetupSSLCAauthentication. If you're still having problems, please file a support ticket.