All Apps and Add-ons

Hostname and index reverts to default

hcpr
Path Finder

Hi,
I just noticed a strange behaviour in the OPSEC LEA add-on.

If I add a CP log connection from the webgui of the app, I change the host and index parameters to match my data layout.
This works fine until I have to temporarily disable the connection.
When I click the 'Diasble" link, those two fields revert back to the default values (index=default and host=)

In the inputs.conf I get the following:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = yyyyyyyyy
index = default
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Where yyyyy is the forwarder hostname.

While I should have:

[script:///opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber.sh --configentity xxxxxxxxxxxx]
disabled = 0
host = xxxxxxx
index = opsec
interval = 30
passAuth = splunk-system-user
sourcetype = opsec

Has anyone else seen this? Any suggestions for how to deal with it (apart from manually changing the values back)?

Thanks.

1 Solution

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

View solution in original post

hcpr
Path Finder

There already is an answer, but just to make the information complete:
splunk-add-on-for-check-point-opsec-lea-linux_210.tgz
And I have tested with both Firefox and IE 10

0 Karma

ilink_splunk
Splunk Employee
Splunk Employee

We have been able to reproduce this issue and have filed a jira ticket: OPSEC-224.

araitz
Splunk Employee
Splunk Employee

One workaround is to enable/disable from the individual connection's edit page. This will result in the host and index attributes not reverting to the default settings.

0 Karma

araitz
Splunk Employee
Splunk Employee

What version of the add-on are you using? What browser?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...