All Apps and Add-ons

Splunk Add-on for Check Point OPSEC LEA: How can I stop the OPSEC LEA 2.0?

skuma30
New Member

Hi,
I'm facing some issues with the old OPSEC LEA. We migrated to the latest version of Splunk Add-on for Check Point OPSEC LEA and trying to stop the logs receiving from the old add-on but some reason it is still receiving the logs. Do you have any thoughts? please share with me.
Thanks

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi skuma30,

Upgrading OPSEC LEA from version 2.x to 4.00 and later is tantamount to installing a completely new add-on. In a strict sense, you do not UPGRADE your old version to 4.0 and beyond but merely disable or uninstall your old add-on and install a new one. Therefore, if you do not disable or uninstall your old version (2.x) OPSEC LEA TA and still leave it running, of course you will still get data ingested into Splunk from that old TA.
For information about OPSEC LEA upgrade, please refer to the Splunk documentation here:
http://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Releasehistory#Migration_guide

Hope this helps. Thanks!
Hunter

aaraneta_splunk
Splunk Employee
Splunk Employee

@skuma30 - Are you using the Splunk Add-on for Check Point OPSEC LEA on Splunkbase? I just want to make sure your post is tagged appropriately. Please let me know.

0 Karma

skuma30
New Member

aareneta[Splunk] yes, Im using the same app but older version not the latest one.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...