All Apps and Add-ons

Hostname and index reverts to default

hcpr
Path Finder

Hi,
I just noticed a strange behaviour in the OPSEC LEA add-on.

If I add a CP log connection from the webgui of the app, I change the host and index parameters to match my data layout.
This works fine until I have to temporarily disable the connection.
When I click the 'Diasble" link, those two fields revert back to the default values (index=default and host=)

In the inputs.conf I get the following:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = yyyyyyyyy
index = default
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Where yyyyy is the forwarder hostname.

While I should have:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = xxxxxxx
index = opsec
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Has anyone else seen this? Any suggestions for how to deal with it (apart from manually changing the values back)?

Thanks.

1 Solution

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

View solution in original post

hcpr
Path Finder

There already is an answer, but just to make the information complete:
splunk-add-on-for-check-point-opsec-lea-linux_210.tgz
And I have tested with both Firefox and IE 10

0 Karma

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

araitz
Splunk Employee
Splunk Employee

One workaround is to enable/disable from the individual connection's edit page. This will result in the host and index attributes not reverting to the default settings.

0 Karma

araitz
Splunk Employee
Splunk Employee

What version of the add-on are you using? What browser?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...