All Apps and Add-ons

Hostname and index reverts to default

hcpr
Path Finder

Hi,
I just noticed a strange behaviour in the OPSEC LEA add-on.

If I add a CP log connection from the webgui of the app, I change the host and index parameters to match my data layout.
This works fine until I have to temporarily disable the connection.
When I click the 'Diasble" link, those two fields revert back to the default values (index=default and host=)

In the inputs.conf I get the following:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = yyyyyyyyy
index = default
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Where yyyyy is the forwarder hostname.

While I should have:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = xxxxxxx
index = opsec
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Has anyone else seen this? Any suggestions for how to deal with it (apart from manually changing the values back)?

Thanks.

1 Solution

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

View solution in original post

hcpr
Path Finder

There already is an answer, but just to make the information complete:
splunk-add-on-for-check-point-opsec-lea-linux_210.tgz
And I have tested with both Firefox and IE 10

0 Karma

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

araitz
Splunk Employee
Splunk Employee

One workaround is to enable/disable from the individual connection's edit page. This will result in the host and index attributes not reverting to the default settings.

0 Karma

araitz
Splunk Employee
Splunk Employee

What version of the add-on are you using? What browser?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...