All Apps and Add-ons

Does the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80?

tallan
Engager

Will the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80? We are in the process of doing an early upgrade on all Checkpoint managers and log servers to R80. The older version of Checkpoint that we were on, R77, is currently supported by the OPSEC LEA add-on and has functioned properly since installation, but I do not see any information or release dates for support of R80. Has anyone tried R80 and the OPSEC LEA add-on?

0 Karma
1 Solution

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

View solution in original post

FrankVl
Ultra Champion

Given that R80 supports syslog forwarding, you might want to take a look a that. Could make your checkpoint data collection a lot easier. You'd need to create a custom TA for it, since the official add-on does not support the syslog format, but apart from the basic field extractions, you can re-use a lot of logic from the original TA.

0 Karma

tonisaprano
New Member

But starting with version 4.0.0 release notes tell that Add-on supports R80. (vendor Products Check Point OPSEC LEA R76, R77, R80). Actually has anybody tried R80 and the OPSEC LEA add-on?

0 Karma

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...