All Apps and Add-ons

Collect log from CheckPoint OPSEC Lea to Splunk Enterprise install on Windows OS

mindterrian
New Member

Hi

How can i collect the CheckPoint OPSEC Lea on Splunk Enterprise that install on Windows OS?
Because this guide (https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Hardwareandsoftwarerequirements) only support on Linux OS.

Thank you

Tags (1)
0 Karma

vishaltaneja070
Motivator

Hello @mindterrian

As per the above document, the add-on supports on Linux in case if you are using Universal Forwarder to collect data.

If you are using any other component like search head or indexer , they can be on any platform.

0 Karma

mindterrian
New Member

Hello @vishaltaneja07011993

My environment is
Splunk Enterprise (Single Instance) install on Windows Werver 2012 R2 and install Splunk Add-on for Check Point OPSEC LEA already.
I can use this Splunk Server to collect log from Check Point via add parameter on Splunk Add-on for Check Point OPSEC LEA right?

Or i need to install Universal forwarder on Linux OS and install Splunk Add-on for Check Point OPSEC LEA after that i will collect log via Universal forwarder?

Thank you

0 Karma

mindterrian
New Member

I can use Splunk Enterprise (Single Instance) that install on Windows OS to collect log from Check Point OPEC LEA via install Splunk Add-on for Check Point OPSEC LEA and Add connect right?

or i should install universal forwarder on Linux OS and use Splunk Add-on for Check Point OPSEC LEA on Linux OS to collect log from Check Point?

0 Karma

dkeck
Influencer

There is an alternate option where you can analyze checkpoint logs via syslog. This add-on will help you analyze Check Point logs on Windows.

https://splunkbase.splunk.com/app/2996/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...